If you use the ChatGPT desktop app on a Mac, you should stop what you’re doing and check for an update. On April 11, 2026, OpenAI issued an urgent advisory requiring all macOS users to update their applications following a significant security scare.

The “Axios” Supply Chain Attack
The urgency isn’t due to a direct hack of OpenAI’s servers, but rather a supply chain attack involving a popular third-party developer library called Axios.
On March 31, 2026, hackers (believed to be state-linked) hijacked an Axios maintainer’s account and pushed malicious code. This malicious version was accidentally pulled into OpenAI’s internal “workflow” used to sign and certify their Mac applications.
Why It’s a Risk: Fake Apps
Because the malicious library had access to OpenAI’s code-signing certificates, there was a hypothetical risk that hackers could create fake ChatGPT apps that appear 100% legitimate to your Mac’s security system.
-
The Good News: OpenAI states there is no evidence that user data was accessed, API keys were stolen, or the actual software was altered.
-
The Precaution: To eliminate any future risk, OpenAI is revoking and rotating its security certificates.
Mandatory Deadline: May 8, 2026
This isn’t an optional update. OpenAI has confirmed that older versions of the ChatGPT Mac app will stop working after May 8, 2026. * Platforms Affected: Only macOS. If you use ChatGPT on Windows, iOS, Android, or the web, you are unaffected.
-
Other Apps: The warning also applies to OpenAI’s other Mac tools, including Codex, Atlas, and the Codex CLI.
How to Secure Your Mac
-
Open ChatGPT on your Mac.
-
Click on the ChatGPT menu in the top bar and select “Check for Updates.”
-
Alternatively, download the fresh, re-certified version directly from OpenAI’s official website.
By updating now, you ensure your app is signed with the new, secure certificate, protecting you from sophisticated “spoofing” attacks that could otherwise bypass macOS’s built-in Gatekeeper protections.















