
One year might be generous. Researchers already showed breaches hitting AI coding tools like Cursor, Codex CLI and Google's Antigravity. There's a live Codex macOS bug, CVE-2026-14898, where the app auto-renders remote images in model responses and leaks sensitive data. Reward hacking in Codex is documented too. So the attack surface is here now, not a year out.
Post summary
The post highlights a documented macOS bug (CVE‑2026‑14898) that allows remote image rendering, potentially leaking sensitive data, but offers no PoC, exploit, patch, or evidence of active attacks.


