Mark RadarMARK RADAR
EN

OpenAI Replaces Certificates After macOS App Security Risk, Urges Users to Update

7 reports · First detected 2026-04-11 · Last active 2026-05-15

OpenAI uses digital certificates to verify the authenticity of its ChatGPT and Codex desktop apps for macOS. Two employee computers were affected after the third-party development tool Axios was compromised in the TanStack software supply-chain attack, creating a risk that signing certificates may have been exposed. If misused, the certificates could allow malware to masquerade as official software, threatening app integrity and user security.

OpenAI confirmed the incident on April 14 and said it had found no evidence that ChatGPT or Codex services or user data were accessed. The company has replaced the potentially affected certificates, released updated versions and told all macOS users to update through official channels. Related reports said ChatGPT and Codex users on macOS must update by June 12 to avoid service disruptions after the old certificates expire.

All Coverage

7 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR