OpenAI’s Silent Breach: Why You Must Update Your macOS ChatGPT App Before May 8
ID: 9ecf3192-96fd-5181-aed5-6b857bcd4073
STIX ID: report--9ecf3192-96fd-5181-aed5-6b857bcd4073
Feed Name: securityonline.info
OpenAI was impacted by a supply-chain incident in late March when a hijacked developer account published a malicious Axios v1.14.1 that was retrieved and executed by its macOS GitHub Actions signing workflow; the event created a theoretical exposure of signing and notarization materials. OpenAI found no evidence of user data compromise, but revoked legacy signing certificates, re-signed affected applications, and requires users to update to specified versions (ChatGPT v1.2026.051, Codex apps and CLI, Atlas) before legacy certificates are nullified on May 8, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
