Codex Remote Control security flaws
Open 💬 1 comment Opened May 15, 2026 by bLightZP
What version of the Codex App are you using (From “About Codex” dialog)?
Codex 26.506.31421
What subscription do you have?
Plus
What platform is your computer?
Windows 10 fully patched
What issue are you seeing?
- Asking Codex to take screenshots of the desktop (which can be viewed remotely), list the content of folders and delete files outside the sandbox in a chat works without any authorization requests (even though the model says that it needs to ask for it), chat set as "Auto-Review" permission.
- When I asked it to run "calc.exe" or other scripts it creates, it asks for permission, which I can easily approve.
- Actions in ChatGPT does not show up in real time in the codex app.
What steps can reproduce the bug?
- I first tested it locally by creating a new chat (not project) with "Auto-Review" permissions and asked it to do several things like taking a screenshot of the desktop, write a powershell script to switch to one of the active apps (firefox) seen in the screenshot and erase a local file residing outside the sandbox. All worked without requesting authorization.
- I then connected to the codex CLI by running "codex.exe remote-control".
- Within ChatGPT (Android), I found the same chat I started on desktop and told it to take a screenshot of desktop, list the content of folders and erase another file outside the sandbox and it did without requesting authorization.
What is the expected behavior?
- Additional security check (fingerprint, pin number, etc) before even allowing me to enter the remote control codex section in ChatGPT.
- Desktop-side controls that allow me to prevent destructive actions taken on ChatGPT even if approved.
Additional information
With the level of security currently in place, bad actors could easily cause havoc on my desktop PC (e.g. run ransomware encryption) if they manage to steal my phone and unlock it.
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗