Tech News
← Home  ·  All topics

Sandbox Escape

2 GoKawiil briefs on this topic

OpenAI Codex sandbox flaws let attackers execute code on developer machines

Security researchers at Accomplish AI discovered two ways to break out of the sandbox that isolates OpenAI's Codex coding agent from a user's system. The worse of the two, dubbed Heapjack, let a malicious repository trigger unsandboxed code execution on a victim's machine simply by having Codex answer a question about that repo's code, with no approval prompt or visible warning. Both bugs were reported to OpenAI on August 12 and patched within eight days.

Security researcher finds single exploit strategy rooting Samsung, Xiaomi, Oppo devices

A security researcher has published a series detailing how an unprivileged Android app can escalate to root access on major OEM devices using one repeatable strategy. The method targets manufacturer-specific kernel driver bugs—specifically page Use-After-Free flaws—reached via OEM-specific sandbox escapes, and was demonstrated on Samsung Galaxy S23 through S26 devices, many Xiaomi mid-range to flagship phones, and recent Oppo, OnePlus, and Realme flagships.