Codex Desktop flaw let untrusted code read auth tokens from shared memory
Researchers detailed a second Codex sandbox escape: untrusted code read authentication tokens from memory shared with the bundled Node.js tool and forged requests to external native programs. The issue was fixed in Codex Desktop 26.818.21641, while the first flaw was patched in Codex CLI 0.149.0.
- Untrusted code read auth tokens from shared Node.js process memory
- The path triggered even in strict read-only mode with no user approval
- Fixed in Codex Desktop 26.818.21641 and Codex CLI 0.149.0
- Both flaws were reported to OpenAI on August 12, 2026
Read next
Security