OpenAI Codex Flaw Let Untrusted AI-Generated Code Steal Auth Tokens from Memory
A sandbox escape vulnerability in OpenAI's Codex desktop edition, disclosed on September 21, 2026, allows untrusted AI-generated code to read authentication tokens from shared process memory. The flaw stems from Codex's bundled Node.js tool running both trusted and AI-generated code within the same memory space, enabling token theft without triggering any visible permission prompts. Stolen credentials can then be used to forge requests to external native programs capable of launching applications, modifying system configurations, or accessing local Unix sockets — constituting a full sandbox escape. Researchers noted that the severity is compounded when agents hold broad, long-lived credentials, as a single memory read could grant prolonged unauthorized access. Since Codex operates primarily on developer workstations rather than internet-facing servers, the true number of affected systems is likely far greater than the 164 instances indexed by external scanners.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in