{"id":424005,"date":"2026-04-11T09:28:52","date_gmt":"2026-04-11T03:58:52","guid":{"rendered":"https:\/\/dripp.zone\/news\/mac-users-update-your-chatgpt-app-immediately-openai-issues-urgent-security-warning-crypto-news\/"},"modified":"2026-04-11T10:46:18","modified_gmt":"2026-04-11T05:16:18","slug":"mac-users-update-your-chatgpt-app-immediately-openai-issues-urgent-security-warning-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/mac-users-update-your-chatgpt-app-immediately-openai-issues-urgent-security-warning-crypto-news\/","title":{"rendered":"Mac users, update your ChatGPT app immediately: OpenAI issues urgent security warning &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<div id=\"article-index-0\">\n<p>OpenAI has confirmed that it had faced a recent security issue involving the third-party developer library Axios, which it says was \u2018part of a broader industry incident\u2019. The ChatGPT maker, in a post on X, says that it found no evidence that its user data was accessed or its systems were compromised or its software was altered in any way.<\/p>\n<\/div>\n<div id=\"article-index-3\">\n<p>\u201cOut of an abundance of caution, we are taking steps to protect the process that certifies our macOS applications are legitimate OpenAI apps,\u201d the company wrote in a post on X.<\/p>\n<\/div>\n<div id=\"article-index-6\">\n<p>\u201cWe are updating our security certifications, which will require all macOS users to update their OpenAI apps to the latest versions. This helps prevent any risk\u2014however unlikely\u2014of someone attempting to distribute a fake app that appears to be from OpenAI. You can update safely through an in-app update or at the official links below,\u201d it added.<\/p>\n<\/div>\n<div id=\"article-index-9\">\n<p>OpenAI has also clarified that the vulnerability is strictly limited to its macOS applications. If you use <a rel=\"nofollow\" target=\"_blank\" class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/technology\/tech-news\/openai-takes-on-anthropic-overhauls-chatgpt-pro-subscription-with-new-ai-plan-heres-what-you-need-to-know-11775785708245.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" data-vars-anchor-text=\"ChatGPT\">ChatGPT<\/a> on <a rel=\"nofollow\" target=\"_blank\" class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/technology\/tech-news\/apple-releases-ios-26-5-beta-1-update-check-top-new-features-how-to-download-and-more-11774923924707.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" data-vars-anchor-text=\"iOS\">iOS<\/a>, Android, Windows, Linux, or through a web browser, you are completely unaffected by this incident.<\/p>\n<\/div>\n<div id=\"article-index-10\">\n<h2>What happened during the security incident?<\/h2>\n<p>The security issue stems from a &#8220;supply chain attack&#8221; on 31, 2026. Instead of attacking OpenAI directly, hackers compromised <a rel=\"nofollow\" target=\"_blank\" class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/news\/us-news\/north-korea-linked-hackers-breach-axios-software-to-target-us-firms-crypto-theft-feared-report-11775049345884.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" data-vars-anchor-text=\"Axios\">Axios<\/a>, a popular online library that developers use to build their software. The company noted in a blog post that a GitHub Actions workflow used in its <a rel=\"nofollow\" target=\"_blank\" class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/technology\/tech-news\/certin-warns-macos-and-chrome-users-of-serious-security-risk-how-to-stay-safe-online-11769836187390.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" data-vars-anchor-text=\"macOS\">macOS<\/a> app-signing process ended up downloading a malicious version of the library.<\/p>\n<\/div>\n<div id=\"article-index-11\">\n<p>This workflow had access to the certificates used to sign Mac applications like ChatGPT Desktop and Codex. The certificate basically tells the operating system that the software comes from a legitimate developer.<\/p>\n<\/div>\n<div id=\"article-index-12\">\n<p>While OpenAI says that its analysis shows the certificate was likely not stolen by the malicious payload, the company says \u2018out of an abundance of caution\u2019, it is treating the certificate as compromised and is revoking and rotating it.<\/p>\n<\/div>\n<div id=\"article-index-13\">\n<h2>Mandatory update for Mac users<\/h2>\n<p>As a result of the security incident, the ChatGPT maker is forcing a mandatory update for its macOS users. The company says older versions of the Mac desktop apps will no longer receive updates or support from 8 May 2026, and they may stop functioning entirely.<\/p>\n<\/div>\n<div id=\"article-index-16\">\n<p>If a bad actor did manage to get their hands on the old certificate, they could technically use it to sign their own code and create fake ChatGPT apps that look legitimate. To counter this, the company has stopped new software notarisation using the old certificate. Once the old certificate is fully revoked in May, macOS security protections will automatically block any new downloads and first-time launches of apps signed with it.<\/p>\n<\/div>\n<div id=\"article-index-17\">\n<p>This means that any fraudulent app posing as an OpenAI app using the impacted certificate will lack notarisation, and therefore will be blocked by default by macOS security protections unless a user explicitly bypasses those protections.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>OpenAI has confirmed that it had faced a recent security issue involving the third-party developer library Axios, which it says was \u2018part of a broader industry incident\u2019. The ChatGPT maker, in a post on X, says that it found no evidence that its user data was accessed or its systems were compromised or its software [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":424018,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[9366,188,183,5834,9367,46641,185,186,187,184,5792,189,150,182,190],"class_list":["post-424005","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-ai-chatgpt","tag-blockchain-tech","tag-blockchain-technology","tag-chatgpt","tag-chatgpt-ai","tag-chatgpt-mac","tag-crypto-technology","tag-cryptocurrency-technology","tag-metaverse-technology","tag-nft-technology","tag-openai","tag-soul-bound-token","tag-tech","tag-technology","tag-token-technology"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/424005","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=424005"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/424005\/revisions"}],"predecessor-version":[{"id":424019,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/424005\/revisions\/424019"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/424018"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=424005"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=424005"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=424005"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}