Impact
The OpenAI Codex desktop app for macOS renders images referenced in Markdown within model responses. Content processed by Codex, such as a connected‑tool result or other untrusted source, can induce the model to construct a remote image URL that includes sensitive data. The application automatically fetches that URL when rendering the response, sending the embedded data to an attacker‑controlled server without a user click. Successful exploitation could exfiltrate secrets and other information accessible in the Codex session, including API keys, source code, and data returned by connected tools. No direct integrity or availability impact has been demonstrated.
Affected Systems
OpenAI Codex desktop application for macOS in all releases prior to version 26.527.31326.
Risk and Exploitability
The EPSS score of < 1% suggests a very low probability of exploitation while the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates moderate severity. An attacker must first gain an indirect prompt injection foothold, typically by providing untrusted content that Codex processes. If successful, the app will fetch the malicious image and transmit the payload to a remote server, resulting in the exfiltration of sensitive session data. No real‑world exploitation evidence is currently available, but the combination of a feasible exploitation path and the potential for data leakage presents a significant confidentiality risk.
OpenCVE Enrichment