chiprook
← Security
SecuritySeptember 25, 2026, 07:20

Codex Desktop flaw let untrusted code read auth tokens from shared memory

Researchers detailed a second Codex sandbox escape: untrusted code read authentication tokens from memory shared with the bundled Node.js tool and forged requests to external native programs. The issue was fixed in Codex Desktop 26.818.21641, while the first flaw was patched in Codex CLI 0.149.0.

Codex Desktop flaw let untrusted code read auth tokens from shared memory
#OpenAI#Codex
Read next
Security

ZoomEye: 9,112 Indexed Kafka Endpoints vs 1,377,501 Services on Port 9092

Security

Hackers Claim Theft of FBI Data With Employee Home Addresses

Security

Better face recognition exposes limits of image quality scores

Security

Plugin4Shell flaw hits Claude Code, Codex, Gemini CLI and Copilot