OpenAI discovers security vulnerability, affirms user data is safe

Cát Tiên |

OpenAI discovered a security vulnerability related to third-party tools, but affirmed that there is no evidence that user data was accessed or compromised.

OpenAI company (ChatGPT's developer) has just confirmed the discovery of a security vulnerability related to third-party tools, but emphasized that no signs of user data being accessed or the system being compromised have been recorded.

According to the announcement, the incident originated from the popular Axios development library, which was identified as having been compromised on March 31 in a large-scale software supply chain attack.

OpenAI said the attack caused their GitHub Actions workflow to accidentally download and execute a malicious version of Axios.

This process has access to authentication certificates and documents used to sign macOS applications such as ChatGPT Desktop, Codex, Codex-cli and Atlas.

However, after analysis, the company affirmed that there is no evidence that these signed certificates were successfully stolen. At the same time, OpenAI also did not record any software changes, intellectual property infringement or unauthorized user data access.

The root cause of the incident was identified as a configuration error in the GitHub Actions process. OpenAI said that this problem has been fixed and additional security measures are being implemented to enhance software supply chain control.

To minimize risks, the company is updating security certificates and requires all macOS users to upgrade the OpenAI application to the latest version.

This move is aimed at preventing the risk of fake applications taking advantage of old certificates to spread malware.

In addition, OpenAI announced that from May 8th, old versions of the ChatGPT application on macOS will no longer be supported or updated, and may stop operating. Users are recommended to update early to ensure safety and stable experience.

Notably, the company also affirmed that users' passwords and API keys are not affected by this incident.

Cát Tiên
RELATED NEWS

AWS talks about investing in OpenAI and Anthropic at the same time

|

AWS affirms that investing in parallel in Anthropic and OpenAI is a survival strategy in the fierce global AI race.

Former OpenAI engineers establish private fund to select potential AI startups

|

Former employees and engineers of OpenAI established the Zero Shot fund, to selectively invest in potential AI startups.

OpenAI adjusts apparatus, preparing for IPO ambitions

|

OpenAI is undergoing major changes in senior personnel in the context of increasingly fierce AI competition and ambitions to expand business products.

The appearance of the 10-lane road in Dong Nai connecting Ho Chi Minh City is about to open to traffic

|

Dong Nai - Road 25B (Ton Duc Thang road) from National Highway 51 to the center of Nhon Trach commune is about to be opened to traffic with 10 lanes.

US declares Iran has no cards left at the negotiating table

|

US-Iran negotiations in Pakistan face many obstacles as disagreements on preconditions have not been resolved.

Exemption from Russian oil sanctions expires today, Asia puts pressure on the US

|

Some Asian countries are putting pressure on the US to extend the easing mechanism of sanctions against Russian oil, while Europe is showing disagreement.

Live football U20 Vietnam women vs U20 Japan women in the Asian quarter-finals

|

Live football match between Vietnam U20 women's team and Japan U20 women's team in the 2026 Asian quarter-finals, taking place at 4:00 PM today (April 11).

Proposal to relax regulations on holiday swaps so that workers can have continuous leave

|

Regulations on compensatory days are still "rigid", making it not feasible to swap working days to extend holidays; many opinions suggest that it should be relaxed in a more flexible direction.

AWS talks about investing in OpenAI and Anthropic at the same time

Cát Tiên |

AWS affirms that investing in parallel in Anthropic and OpenAI is a survival strategy in the fierce global AI race.

Former OpenAI engineers establish private fund to select potential AI startups

Cát Tiên |

Former employees and engineers of OpenAI established the Zero Shot fund, to selectively invest in potential AI startups.

OpenAI adjusts apparatus, preparing for IPO ambitions

Cát Tiên |

OpenAI is undergoing major changes in senior personnel in the context of increasingly fierce AI competition and ambitions to expand business products.