OpenAI Replaces Certificates After macOS App Security Risk, Urges Users to Update
OpenAI uses digital certificates to verify the authenticity of its ChatGPT and Codex desktop apps for macOS. Two employee computers were affected after the third-party development tool Axios was compromised in the TanStack software supply-chain attack, creating a risk that signing certificates may have been exposed. If misused, the certificates could allow malware to masquerade as official software, threatening app integrity and user security.
OpenAI confirmed the incident on April 14 and said it had found no evidence that ChatGPT or Codex services or user data were accessed. The company has replaced the potentially affected certificates, released updated versions and told all macOS users to update through official channels. Related reports said ChatGPT and Codex users on macOS must update by June 12 to avoid service disruptions after the old certificates expire.
All Coverage
7 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.