macOS detects Codex Computer Use.app as malware and deletes it!

Resolved 💬 4 comments Opened Jul 6, 2026 by dgobaud Closed Jul 6, 2026

What version of the Codex App are you using (From “About Codex” dialog)?

Version 26.623.101652 • Released Jul 2, 2026

What subscription do you have?

Plus

What platform is your computer?

Darwin 25.5.0 arm64 arm

What issue are you seeing?

Just opened Codex and I think it wanted to update and I let it and then immediately got this macOS malware dialog and it deleted Codex Computer User.app!

I then asked Codex about this ("macOS detected your Codex Computer Use.app as malware and moved it to the trash!! is this a problem...?") giving it the screenshots and it replied below:

Yes, it’s a problem in the sense that you should not restore or whitelist that app from Trash.

What I found:

So: your Mac probably protected you, and this does not mean your whole Mac is compromised. But your local Codex install should be treated as untrusted until replaced.

Do this:

  1. Leave the trashed Codex Computer Use.app in the Trash, or empty Trash.
  2. Quit Codex.
  3. Delete /Applications/Codex.app.
  4. Reinstall Codex only from the official OpenAI/Codex source.
  5. Open Codex, then reinstall Computer Use from Codex Settings if you need it.
  6. Re-grant Screen Recording and Accessibility only after the fresh install.

I would not try to manually move the helper back, bypass Gatekeeper, or run xattr fixes here. The invalid signature makes “clean reinstall” the sane path.

<img width="244" height="253" alt="Image" src="https://github.com/user-attachments/assets/ed196cb3-439f-47e0-91a2-a940ae41b717" />

<img width="425" height="497" alt="Image" src="https://github.com/user-attachments/assets/260dfa3b-df26-49d6-ac5f-3689ecba8236" />

What steps can reproduce the bug?

open Codex and do auto-update

What is the expected behavior?

Codex Computer Use.app to not be detected as malware by macOS

Additional information

n/a

View original on GitHub ↗

This issue has 4 comments on GitHub. Read the full discussion on GitHub ↗