Weak Codex Mobile Security

Open 💬 0 comments Opened Jul 9, 2026 by Datakunskap

What version of the Codex App are you using (From “About Codex” dialog)?

26.623.141536

What subscription do you have?

Pro

What platform is your computer?

Darwin 25.4.0 arm64 arm

What issue are you seeing?

Secure key exchange should be integrated into the Mobile QR auth flow ASAP. This is extremely unsecure. I was able to access my MacBook remotely (via iOS) solely with having OpenAI account access (no QR code needed).

Also, preferably e2e encrypted “relay layer” to better protect everyone’s IP 🙏.

What steps can reproduce the bug?

Normal device connection flow for connecting ChatGPT Mobile iOS device to Codex App on MacBook. No MacBook access or QR code needed…

What is the expected behavior?

_No response_

Additional information

_No response_

View original on GitHub ↗