OpenAI Flags Third-Party Data Issue – All macOS Users Should Update Now


  • OpenAI rotated macOS code signing certificate after Axios supply chain breach
  • Malicious Axios 1.14.1 pulled into app signing workflow
  • No evidence of data theft, but older app versions out of date

OpenAI recently rotated its macOS code signing certificate and pushed new versions of macOS products as a proactive measure against potential malware attacks.

When an app is signed with a valid developer certificate (such as OpenAI’s), the system assumes that the developer has been verified, that the app has not been tampered with, and that it is safe to run. Having malware signed with one of these certificates almost guarantees that it will bypass protections and be allowed to run on the endpoint.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top