Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
OpenAI fixed two Codex sandbox escape vulnerabilities after researchers showed how malicious code could bypass key security restrictions.
Codex sandbox escapes called Overpatch and Heapjack crossed isolation boundaries. Fixed versions show why trusted helper ...