OpenAI has issued a warning to users of its apps on MacBook and Apple desktops regarding a recent security concern. The security breach occurred on March 31 during a broader software supply chain attack targeting a third-party tool called Axios, commonly used by developers. OpenAI utilizes Axios tools to verify the authenticity of its macOS applications.
Although OpenAI assures that no user data was compromised and their systems and intellectual property remain secure, users are urged to take precautionary measures by updating their apps. The company is in the process of updating security certificates for its applications and advises users to update their macOS apps promptly to safeguard against potential distribution of fake apps, such as ChatGPT Desktop, Codex App, Codex CLI, and Atlas.
The security incident was triggered by OpenAI’s automated system, GitHub Actions, which builds and certifies apps to confirm their legitimacy. This system inadvertently downloaded a tainted version of Axios during the attack, leading to the execution of compromised code.
OpenAI has confirmed that the attackers did not succeed in stealing the app legitimacy certificate. Nevertheless, as a preventive measure, the company is invalidating the old certificate and transitioning to a new one. Consequently, older versions of the apps will no longer receive updates or support and will cease to function after May 8, 2026.
Users need not change their passwords since passwords and OpenAI API keys were unaffected by the breach. The security compromise has not impacted apps on other operating systems like Android, Linux, or Windows. However, macOS users are strongly advised to update their apps to ensure they are operating on the latest versions with updated security certificates.
OpenAI has blocked the use of old certificates, which might prompt macOS to restrict new downloads and app signing. To facilitate the update process, users are granted a 30-day window to update their apps through the built-in update mechanism provided by OpenAI.

