OpenAI warns Mac users: update ChatGPT, Codex, Atlas by June 12 after npm supply-chain attack
Signing certificates exposed – patch these three Mac apps before the June 12 deadline.
Deep Dive
OpenAI says Mac users must update ChatGPT, Codex, and Atlas apps by June 12 after an npm supply-chain attack exposed signing certificates.
Key Points
- OpenAI warns Mac users to update ChatGPT, Codex, and Atlas apps by June 12.
- The attack compromised npm packages used in build pipeline, exposing signing certificates.
- Only macOS builds are affected; Windows and Linux users are not at risk.
Why It Matters
Compromised code-signing certificates could let attackers distribute malware disguised as trusted OpenAI apps.