OpenAI identifies security issue involving third-party tool, says user data was not accessed

OpenAI identifies security issue involving third-party tool, says user data was not accessed


Samuel Boivin | Nurphoto | Getty Images

OpenAI said on Friday it had identified a security issue involving a third-party developer tool called Axios and is taking steps to protect the process that certifies its macOS applications are legitimate OpenAI apps.

The ChatGPT maker said it found no evidence that its user data was accessed, that its systems or intellectual property was compromised, or that its software was altered.

* The company said it is updating its security certifications, requiring all macOS users to update their OpenAI apps to the latest versions to help prevent any risk of someone attempting to distribute a fake app.

* According to OpenAI, Axios, a widely used third-party developer library, was compromised on March 31, as part of a broader software supply chain attack by actors believed to be linked to North Korea.

* This attack led a GitHub Actions workflow used by OpenAI to download and execute a ‘malicious’ version of Axios. This workflow had access to a certificate and notarization material used for signing macOS applications, including ChatGPT Desktop, Codex, Codex-cli, and Atlas.

* OpenAI said its analysis of the incident concluded that the signing certificate present in this workflow was likely not successfully exfiltrated by the ‘malicious’ payload.

* Effective May 8, older versions of OpenAI’s macOS desktop apps will no longer receive updates or support, and may not be functional, the ChatGPT maker said.

* Passwords and OpenAI API keys were not affected by the third-party security issue, the company said, adding that the root cause of the security incident was a misconfiguration in the GitHub Actions workflow, which has been addressed.

Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.



Source

Iran war, U.S. court’s tariff ruling delays India trade deal — but a bigger risk lies ahead
World

Iran war, U.S. court’s tariff ruling delays India trade deal — but a bigger risk lies ahead

The Indian flag flies in front of billboards featuring images of Indian Prime Minister Narendra Modi and U.S. President Donald Trump in Ahmedabad, India, on Feb. 23, 2020. Bloomberg | Bloomberg | Getty Images The India-U.S. trade deal remains unsigned after months of negotiations, with the Iran war and a U.S. court ruling against tariffs […]

Read More
Global stock markets are too inflated and will fall, top Bank of England official warns
World

Global stock markets are too inflated and will fall, top Bank of England official warns

A trader works on the floor at the New York Stock Exchange (NYSE) in New York City, U.S., April 23, 2026. Jeenah Moon | Reuters International equity markets are priced too high and will fall, according to a senior leader at the Bank of England. Sarah Breeden, deputy governor for financial stability at the U.K.’s […]

Read More
Porsche is selling its Bugatti Rimac stake and walking away from Rimac
World

Porsche is selling its Bugatti Rimac stake and walking away from Rimac

LAS VEGAS, NEVADA – JANUARY 06: People visit Bugatti booth during the Consumer Electronics Show (CES) 2026 on January 6, 2026 in Las Vegas, Nevada. Zhang Shuo | China News Service | Getty Images Porsche AG has agreed to sell its 45% stake in supercar brand Bugatti Rimac, fully exiting the joint venture that houses […]

Read More