Researchers broke out of OpenAI Codex's sandbox — twice
Security researchers found two ways to escape the protective sandbox used by OpenAI’s Codex coding agent, including one that could run commands on a developer’s computer without an approval prompt. The vulnerabilities, named Heapjack and Overpatch, affected different parts of Codex and were discovered by security researcher Oren Yomtov of Accomplish AI. Get updated faster and for FREE: Download…
Two security vulnerabilities, dubbed Heapjack and Overpatch, have been discovered in OpenAI Codex's protective sandbox, allowing researchers to break out of the sandbox twice. Accomplish AI researcher Oren Yomtov revealed the flaws, which were subsequently fixed by OpenAI within eight days of reporting. Heapjack, a JavaScript component in Codex Desktop, enabled exploitation even in read-only mode, while Overpatch manipulated the open-source Codex command-line tool's patching mechanism.
Both vulnerabilities stemmed from security controls relying on potentially manipulated information. Codex users are advised to update to Codex Desktop build 26.818.21641 or later, and Codex CLI 0.149.0 or later to mitigate the risks.
Written by urgent.news from Gulf News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Researchers penetrate OpenAI systems with Claude models thearabianpost.com