OpenAI Codex Bug Secretly Sends Private Local Chat Data to OpenAI Servers Without User Consent
Summary
A critical bug in OpenAI Codex v0.150.0-alpha.12.2 is secretly transmitting private local chat data — including messages, tool calls, and environment data — to OpenAI's servers without user consent, even when telemetry is fully disabled, prompting urgent demands for a public incident response and full account audit.
Key Points
- A critical bug in OpenAI Codex desktop app (v0.150.0-alpha.12.2) allows the Memories feature to select chat rollouts from local or third-party providers and transmit their contents to OpenAI's servers without user knowledge or consent, even when analytics and telemetry are fully disabled.
- The provider crossover occurs because memory candidate selection is not bound to the source rollout's original provider, meaning an OpenAI-backed session can claim and serialize private local-provider conversations — including user messages, tool calls, tool outputs, and environment data — and send them to chatgpt.com for remote processing.
- The reporter, who triggered this investigation after receiving an unexpected OpenAI account warning for content that only existed in private local-provider chats, is demanding an official public incident response, an audit of all affected accounts, reversal of any negative actions derived from this data, and a fix that enforces strict provider isolation before any memory transmission occurs.