Risky Business · Wednesday, September 23, 2026
A bug in OpenAI's Codex sandboxing environment has been discovered, allowing for privilege escalation. James described the implementation as a "comedy control" that lacked proper thought, contrasting it with more robust sandboxing techniques used by companies like Chrome and Apple.
“We've got one issue here involving like problems with the Codex sandboxes, is that right?”
“Yeah, they, um, there was an issue where, uh, there's kind of like two components, uh, in Codex, like two JavaScript threads, I suppose. One kind of responsible for privileged access, and one responsible for, like, unprivileged access. Uh, and someone found a bug where you could just like, you're in the same process memory. You could just help yourself to the tokens for the privileged bit, uh, and, you know, escalate out of the sandbox.”
“And then you see this kind of like comedy, uh, you know, I guess control that, um, they're like, just whack a sandbox in, make it feel good, uh, with like no actual thought about how this should actually work, no actual structures.”