Home News Security Flaws Found in OpenAI Codex

Researchers Uncover Security Flaws in OpenAI Codex

Sep 21, 2026
56 min
3
Sep 21, 2026 13:30
Researchers broke out of OpenAI Codex's sandbox — twice

## Vulnerabilities Discovered

Security experts identified two significant vulnerabilities in OpenAI's Codex coding agent, allowing them to bypass its protective sandbox. These flaws, named Heapjack and Overpatch, were discovered by Oren Yomtov from Accomplish AI.

## Heapjack Vulnerability

Heapjack, the more severe issue, impacted a JavaScript component in Codex Desktop. It allowed malicious code to execute commands on a developer's computer without any approval prompts, even in read-only mode.

## Overpatch Vulnerability

The second flaw, Overpatch, affected the Codex command-line tool. It enabled unauthorized code to write outside its designated workspace, potentially executing when a terminal was opened.

## Quick Response

Both vulnerabilities were reported to OpenAI on August 12 and were patched within eight days. Users are advised to update to Codex Desktop build 26.818.21641 and Codex CLI 0.149.0 or later to ensure security.

## Implications for AI Security

These findings underscore the growing security challenges as AI systems gain more access to interact with computers and development tools. Although there is no evidence of these vulnerabilities being exploited in the wild, they highlight the need for robust security measures in AI applications.

Read the full story at the source

What you need to know to get Emirates ID?

Leave your details and get a guide as a gift to avoid mistakes

Guide illustration
Article contents