High CPU Usage Triggered by Windows Defender & WMI When Launching Codex Desktop on Windows 10
What version of the Codex App are you using (From “About Codex” dialog)?
Codex Desktop Version: 26.715.2305.0
What subscription do you have?
pro 20x
What platform is your computer?
windows
What issue are you seeing?
High CPU Usage Triggered by Windows Defender & WMI When Launching Codex Desktop on Windows 10
Environment
OS: Windows 10 Pro x64
CPU: Intel Core i5-10400F
RAM: 16 GB
GPU: NVIDIA GTX 1650
Codex Desktop Version: 26.715.2305.0
Installation: Microsoft Store
Summary
Launching Codex Desktop immediately causes extremely high CPU usage, even before opening any project.
The CPU reaches 90–100% due to the combination of:
ChatGPT / Codex processes
Windows Defender (Antimalware Service Executable)
WMI Provider Host (WmiPrvSE.exe)
This significantly increases CPU temperature and system load.
Expected Behavior
Opening Codex Desktop without opening any project should result in minimal CPU usage (similar to VS Code extension).
Actual Behavior
Immediately after launching Codex Desktop:
CPU usage jumps to 90–100%.
Windows Defender starts consuming 20–40% CPU.
WMI Provider Host also starts consuming 10–20% CPU.
CPU temperature increases accordingly.
This happens even while sitting on the Home screen without opening any workspace.
Troubleshooting Performed
I tested all of the following:
✅ Replaced CPU thermal paste.
✅ Verified CPU cooler installation.
✅ Tested CPU temperatures (hardware is working normally).
✅ Added Windows Defender exclusions for:
Project folder
C:\Users\<user>\AppData\Local\OpenAI
...\Codex\runtimes
✅ Restarted Windows.
✅ Disabled Windows Defender Real-time Protection.
✅ Tested without opening any project.
✅ Tested after removing NVIDIA RTX Voice.
✅ Checked WMI logs.
✅ Rebuilt Windows Performance Counters.
✅ Verified CPU is normal outside Codex.
None of these resolved the issue.
Important Observation
When Real-time Protection is disabled:
Windows Defender CPU usage disappears.
Codex CPU usage increases instead.
This suggests Defender is scanning Codex activity rather than being the original source.
Comparison with VS Code
Using the Codex extension inside VS Code:
CPU usage remains around 40–70%
No abnormal Defender behavior.
Much lower overall system load.
Only Codex Desktop reproduces this issue.
WMI Activity
Windows Event Viewer shows continuous WMI queries such as:
Win32_Processor
Win32_OperatingSystem
Win32_PerfFormattedData_PerfProc_Process
WMI Provider Host becomes active immediately after launching Codex Desktop.
Additional Notes
The issue occurs:
without opening any project
after reboot
with Defender exclusions configured
even on the Home screen
This suggests the desktop application itself is triggering excessive background activity that causes Defender and WMI to become heavily active.
Request
Could the team investigate whether the current Windows Desktop build performs excessive background indexing, WMI queries, or runtime initialization that triggers Microsoft Defender?
The behavior appears specific to Codex Desktop, since the VS Code extension does not reproduce the same level of CPU usage.
What steps can reproduce the bug?
High CPU Usage Triggered by Windows Defender & WMI When Launching Codex Desktop on Windows 10
Environment
OS: Windows 10 Pro x64
CPU: Intel Core i5-10400F
RAM: 16 GB
GPU: NVIDIA GTX 1650
Codex Desktop Version: 26.715.2305.0
Installation: Microsoft Store
Summary
Launching Codex Desktop immediately causes extremely high CPU usage, even before opening any project.
The CPU reaches 90–100% due to the combination of:
ChatGPT / Codex processes
Windows Defender (Antimalware Service Executable)
WMI Provider Host (WmiPrvSE.exe)
This significantly increases CPU temperature and system load.
Expected Behavior
Opening Codex Desktop without opening any project should result in minimal CPU usage (similar to VS Code extension).
Actual Behavior
Immediately after launching Codex Desktop:
CPU usage jumps to 90–100%.
Windows Defender starts consuming 20–40% CPU.
WMI Provider Host also starts consuming 10–20% CPU.
CPU temperature increases accordingly.
This happens even while sitting on the Home screen without opening any workspace.
Troubleshooting Performed
I tested all of the following:
✅ Replaced CPU thermal paste.
✅ Verified CPU cooler installation.
✅ Tested CPU temperatures (hardware is working normally).
✅ Added Windows Defender exclusions for:
Project folder
C:\Users\<user>\AppData\Local\OpenAI
...\Codex\runtimes
✅ Restarted Windows.
✅ Disabled Windows Defender Real-time Protection.
✅ Tested without opening any project.
✅ Tested after removing NVIDIA RTX Voice.
✅ Checked WMI logs.
✅ Rebuilt Windows Performance Counters.
✅ Verified CPU is normal outside Codex.
None of these resolved the issue.
Important Observation
When Real-time Protection is disabled:
Windows Defender CPU usage disappears.
Codex CPU usage increases instead.
This suggests Defender is scanning Codex activity rather than being the original source.
Comparison with VS Code
Using the Codex extension inside VS Code:
CPU usage remains around 40–70%
No abnormal Defender behavior.
Much lower overall system load.
Only Codex Desktop reproduces this issue.
WMI Activity
Windows Event Viewer shows continuous WMI queries such as:
Win32_Processor
Win32_OperatingSystem
Win32_PerfFormattedData_PerfProc_Process
WMI Provider Host becomes active immediately after launching Codex Desktop.
Additional Notes
The issue occurs:
without opening any project
after reboot
with Defender exclusions configured
even on the Home screen
This suggests the desktop application itself is triggering excessive background activity that causes Defender and WMI to become heavily active.
Request
Could the team investigate whether the current Windows Desktop build performs excessive background indexing, WMI queries, or runtime initialization that triggers Microsoft Defender?
The behavior appears specific to Codex Desktop, since the VS Code extension does not reproduce the same level of CPU usage.
What is the expected behavior?
_No response_
Additional information
High CPU Usage Triggered by Windows Defender & WMI When Launching Codex Desktop on Windows 10
Environment
OS: Windows 10 Pro x64
CPU: Intel Core i5-10400F
RAM: 16 GB
GPU: NVIDIA GTX 1650
Codex Desktop Version: 26.715.2305.0
Installation: Microsoft Store
Summary
Launching Codex Desktop immediately causes extremely high CPU usage, even before opening any project.
The CPU reaches 90–100% due to the combination of:
ChatGPT / Codex processes
Windows Defender (Antimalware Service Executable)
WMI Provider Host (WmiPrvSE.exe)
This significantly increases CPU temperature and system load.
Expected Behavior
Opening Codex Desktop without opening any project should result in minimal CPU usage (similar to VS Code extension).
Actual Behavior
Immediately after launching Codex Desktop:
CPU usage jumps to 90–100%.
Windows Defender starts consuming 20–40% CPU.
WMI Provider Host also starts consuming 10–20% CPU.
CPU temperature increases accordingly.
This happens even while sitting on the Home screen without opening any workspace.
Troubleshooting Performed
I tested all of the following:
✅ Replaced CPU thermal paste.
✅ Verified CPU cooler installation.
✅ Tested CPU temperatures (hardware is working normally).
✅ Added Windows Defender exclusions for:
Project folder
C:\Users\<user>\AppData\Local\OpenAI
...\Codex\runtimes
✅ Restarted Windows.
✅ Disabled Windows Defender Real-time Protection.
✅ Tested without opening any project.
✅ Tested after removing NVIDIA RTX Voice.
✅ Checked WMI logs.
✅ Rebuilt Windows Performance Counters.
✅ Verified CPU is normal outside Codex.
None of these resolved the issue.
Important Observation
When Real-time Protection is disabled:
Windows Defender CPU usage disappears.
Codex CPU usage increases instead.
This suggests Defender is scanning Codex activity rather than being the original source.
Comparison with VS Code
Using the Codex extension inside VS Code:
CPU usage remains around 40–70%
No abnormal Defender behavior.
Much lower overall system load.
Only Codex Desktop reproduces this issue.
WMI Activity
Windows Event Viewer shows continuous WMI queries such as:
Win32_Processor
Win32_OperatingSystem
Win32_PerfFormattedData_PerfProc_Process
WMI Provider Host becomes active immediately after launching Codex Desktop.
Additional Notes
The issue occurs:
without opening any project
after reboot
with Defender exclusions configured
even on the Home screen
This suggests the desktop application itself is triggering excessive background activity that causes Defender and WMI to become heavily active.
Request
Could the team investigate whether the current Windows Desktop build performs excessive background indexing, WMI queries, or runtime initialization that triggers Microsoft Defender?
The behavior appears specific to Codex Desktop, since the VS Code extension does not reproduce the same level of CPU usage.
9 Comments
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action
Happening all the time on my Win machine, Version 26.715.21425
Every Codex app start, and every task start in Codex.
This is a blocker, its taking all the cpu.
I can confirm this issue still exists on Windows 11 with the latest desktop release 26.715.31251.
I tested the following:
ChatGPT Classic does not reproduce the issue.
Opening Codex without opening any workspace immediately causes WMI Provider Host and Windows Management Instrumentation CPU usage to increase.
Closing Codex immediately returns CPU usage to normal.
winmgmt /verifyrepository reports "WMI repository is consistent".
Microsoft Defender exclusions did not resolve the issue.
This appears to affect at least Windows 10 and Windows 11.
I’m experiencing what appears to be the same issue on Windows 11.
System:
When Codex is open, total CPU usage stays around 34–41%, even when no task is actively running. The mouse and the entire Windows interface begin to stutter.
The following processes showed noticeable CPU usage:
After completely terminating Codex through Task Manager:
After launching Codex again, the CPU load immediately increased and the stuttering returned.
This strongly suggests that Codex is triggering additional CPU activity in Microsoft Defender and WMI. The issue is reproducible after restarting Codex.
I also captured and uploaded a performance trace while the issue was occurring.
Feedback ID:
019f7532-b24d-7a53-899d-f973659191c4<img width="733" height="592" alt="Image" src="https://github.com/user-attachments/assets/fadacb33-2bb8-4649-be14-b37109dbd753" />
<img width="756" height="592" alt="Image" src="https://github.com/user-attachments/assets/f690e3c8-a3fc-4af0-9598-70cbb21084ba" />
I can confirm this on another Windows 11 system, with additional WMI/Delivery Optimization evidence.
Environment
26200.8875OpenAI.Codex 26.715.4045.01125.27.50.919(current ASUS release)Observed behavior
WMI evidence
The WMI Activity/Operational log recorded Event ID 5858 every ~2 seconds:
The client PID consistently mapped to the Windows Delivery Optimization service (
DoSvc). Temporarily stoppingDoSvcimmediately stopped the repeated NetAdapter WMI events and WMI CPU usage.DoSvcitself is configured normally as Automatic (Delayed Start).One captured occurrence overlapped a Store acquisition/reinstall:
731,261,669bytes forOpenAI.CodexThis suggests at least part of the Windows-specific CPU spike involves the Store/MSIX update path activating
DoSvc, which then repeatedly queries NetAdapter statistics. The app/Store trigger and the WMI provider load may be overlapping aspects of the same regression.I can reproduce this on another Windows 11 x64 machine with the current Microsoft Store build, and the process breakdown is consistent with this issue.
Environment
OpenAI.Codex_26.715.4045.0_x6410.0.2610031.0.101.4502Reproduction
The Codex CLI by itself does not reproduce the same CPU behavior.
Measurements
A 10.02-second sample produced the following values. “One-core %” treats one logical processor as 100%; “system %” is normalized across all 32 logical processors.
| Process group | One-core % | System % |
|---|---:|---:|
|
ChatGPT.exe| 29.8% | 0.93% ||
WmiPrvSE.exe| 15.6% | 0.49% ||
MsMpEng.exe| 14.0% | 0.44% || bundled
codex.exe| 0.2% | ~0% |The combined value is approximately 59.6% of one logical CPU core (about 1.86% of the whole 32-thread system), which matches the user-visible ~60% reading.
A separate 15-second sample of the desktop process tree after restart showed approximately:
| Desktop process | One-core % |
|---|---:|
|
ChatGPT.exemain | 30.1% || GPU process | 9.5% |
| renderer | 8.9% |
|
codex.exe app-server| 1.4% || Total | 50.0% |
The previous launch produced essentially the same result: 51.1% of one core. Restarting did not materially change it.
Additional observations
Expected behavior: when there is no build/test/browser workload, the desktop shell and its WMI/Defender side effects should settle close to idle instead of continuously consuming roughly half of a logical CPU core.
I found that the high CPU usage (both ChatGPT/Codex, and WMIProvider) can be triggered, if you hover your mouse on the (projects) sidebar, and move quickly up and down.
I have the same issue. Constant WMI and Antimaleware CPU activity while Codex is open.
This looks related to #34014, although it may not have exactly the same trigger.
The important difference is that this issue reproduces on the Home screen without opening a repository, while my reproduction required opening a repository with a very large dirty working tree. The existing report that rapidly hovering over projects in the sidebar can trigger the problem also suggests that project/sidebar metadata refresh may be another entry point.
In my reproduction, WMI Provider Host and Defender were downstream effects rather than the original workload. The standalone app continuously created and cancelled short-lived Git processes:
git.exeprocesses per 10 secondstaskkill.exeprocesses per 10 secondsconhost.exeprocesses per 10 secondsThe parent was the main
ChatGPT.exeprocess. Repeated commands includedgit config,git hash-object, per-filegit diff, andtaskkill /t /f.Reducing the repository from 2,286 untracked files to 10 stopped the process storm:
git.exeprocesses: 0taskkill.exeprocesses: 0Full process-level evidence and the workaround are documented here:
https://github.com/openai/codex/issues/34014#issuecomment-5026272173
This suggests there may be at least two standalone-app triggers:
Both may share the same underlying problem: refreshes are not sufficiently coalesced or debounced, causing repeated local process creation and cancellation. It may be useful to instrument Git worker invocations, child-process creation rate, and sidebar/project metadata refresh separately.