JAZB VTT-006-v1.1: OpenAI Codex Sandbox Escape: Overpatch and Heapjack

JAZB VTT-006-v1.1 is an incident-informed validation exercise evaluating JAZB Framework Version 1.1 against the Overpatch and Heapjack sandbox-escape techniques disclosed for OpenAI Codex. The exercise deliberately grants the adversary the material technical successes described in the public research, including write capability beyond the intended workspace, recovery of a trusted runtime token, and delivery of forged requests to an unsandboxed native parent. JAZB receives no credit for assuming that the underlying sandbox protections remain intact. The exercise compares a mature contemporary cybersecurity and AI-governance baseline with an otherwise matched environment implementing the full applicable JAZB v1.1 capability set. Overpatch tests whether legitimate repository-write Authority can be widened through attacker-controlled path information and indirection until the effective target becomes an out-of-Scope host resource. Heapjack tests whether possession of a trusted technical token can be converted into legitimate Authority to invoke unsandboxed host capabilities. Under the stated full-implementation assumptions, the primary unauthorized host-action objective receives a PASS / PREVENTED disposition. Technical compromise does not create legitimate Authority. JAZB v1.1 applies effective-target validation, method-aware Authority, transitive-capability constraints, persistent behavioral state, repeated-circumvention correlation, and enforcement-path coverage to prevent or contain the tested actions. Where a consequential host path bypasses required JAZB governance or Actuation mediation and no equivalent control reliably prevents it, the result is classified as Governance Escape / implementation nonconformance, not as successful JAZB prevention. The exercise does not independently reproduce the disclosed vulnerabilities, does not claim that remediated systems remain vulnerable, and does not attribute JAZB architecture to OpenAI or any affected product. Central validation principle: Escaping the sandbox does not escape Authority.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-03
DOI
https://doi.org/10.5281/zenodo.23124220
Primary Topic
Security and Verification in Computing
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

JAZB VTT-006-v1.1: OpenAI Codex Sandbox Escape: Overpatch and Heapjack

Michael Costner
Zenodo (CERN European Organization for Nuclear Research)
Security and Verification in Computing
article

JAZB VTT-006-v1.1: OpenAI Codex Sandbox Escape: Overpatch and Heapjack

Michael Costner
article en

Abstract

JAZB VTT-006-v1.1 is an incident-informed validation exercise evaluating JAZB Framework Version 1.1 against the Overpatch and Heapjack sandbox-escape techniques disclosed for OpenAI Codex. The exercise deliberately grants the adversary the material technical successes described in the public research, including write capability beyond the intended workspace, recovery of a trusted runtime token, and delivery of forged requests to an unsandboxed native parent. JAZB receives no credit for assuming that the underlying sandbox protections remain intact. The exercise compares a mature contemporary cybersecurity and AI-governance baseline with an otherwise matched environment implementing the full applicable JAZB v1.1 capability set. Overpatch tests whether legitimate repository-write Authority can be widened through attacker-controlled path information and indirection until the effective target becomes an out-of-Scope host resource. Heapjack tests whether possession of a trusted technical token can be converted into legitimate Authority to invoke unsandboxed host capabilities. Under the stated full-implementation assumptions, the primary unauthorized host-action objective receives a PASS / PREVENTED disposition. Technical compromise does not create legitimate Authority. JAZB v1.1 applies effective-target validation, method-aware Authority, transitive-capability constraints, persistent behavioral state, repeated-circumvention correlation, and enforcement-path coverage to prevent or contain the tested actions. Where a consequential host path bypasses required JAZB governance or Actuation mediation and no equivalent control reliably prevents it, the result is classified as Governance Escape / implementation nonconformance, not as successful JAZB prevention. The exercise does not independently reproduce the disclosed vulnerabilities, does not claim that remediated systems remain vulnerable, and does not attribute JAZB architecture to OpenAI or any affected product. Central validation principle: Escaping the sandbox does not escape Authority.

Zenodo (CERN European Organization for Nuclear Research)
Openalex Percentile: Top 9%
Security and Verification in Computing
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

JAZB VTT-006-v1.1: OpenAI Codex Sandbox Escape: Overpatch and Heapjack — Michael Costner · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS