ACVE-2026-0443
Codex Desktop before build 26.818.21641, running in read-only mode, let untrusted code use a token in the shared process heap to reach unsandboxed command execution.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
In the wild
demonstrated
Description
What
Accomplish reported Heapjack in the JavaScript tool installed by Codex Desktop. The sandbox remained active, but an authentication token in shared memory was accessible to untrusted code and could be used to reach unsandboxed command execution even in read-only mode.
Detection
Accomplish reported a proof of concept and says Codex Desktop build 26.818.21641 closes Heapjack.
Fix
Upgrade Codex Desktop to build 26.818.21641 or later.
Fix
Upgrade Codex Desktop to build 26.818.21641 or later.
- Upgrade
harness:codex-desktopto26.818.21641. The report identifies this as the Heapjack fix. Owner: operator