ChatGPT Mac App Flaw Exposed Deep System Access Risks

A critical vulnerability in the macOS version of ChatGPT, discovered by Objective-See Foundation researchers, could have allowed attackers to access sensitive user data and execute commands. The flaw, which required only about ten lines of code to exploit, was patched by OpenAI on September 25, 2026. It highlighted the security risks of granting AI agents broad system permissions.
Key points
- Objective-See Foundation identified a flaw in ChatGPT’s macOS app that bypassed digital signature checks.
- The vulnerability allowed attackers to access chat logs, browser sessions, and other sensitive data.
- OpenAI acknowledged and patched the issue on September 25, 2026.
- The exploit required pre-existing malware on the victim’s machine but was described as 'insanely trivial' to execute.
- Researchers noted that AI agents’ broad system access creates significant security risks.
Background
This incident follows a trend of expanding AI agent capabilities on macOS, including recent integrations with Apple Messages and writing style features that require broad permissions. Previous coverage noted concerns about AI accessing sensitive data, such as work emails and personal messages, raising questions about the security implications of deep system integration.
How outlets are covering it
WIRED and Mezha both reported on the vulnerability, emphasizing the ease of exploitation and the risks of AI agents having broad system access. WIRED highlighted the 'insanely trivial' nature of the exploit and OpenAI’s acknowledgment of the need for faster security responses. Mezha focused on the technical details of the bypass and the broader implications for AI security. Both sources cited Patrick Wardle of Objective-See Foundation, who criticized AI companies for prioritizing features over security.
Why it matters
The vulnerability underscores the security risks of granting AI agents deep system access, potentially exposing sensitive user data to attackers. It highlights the need for robust security measures in AI applications and the importance of balancing feature development with security concerns.
What to watch
OpenAI has patched the vulnerability, but researchers are continuing to identify and report new issues, including a recent finding related to ChatGPT’s integration with the Dots AI assistant. The broader industry is expected to face increased scrutiny on security practices as AI agents become more prevalent.
- A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data WIRED
- ChatGPT for Mac Security Flaw Leaves Users’ Chat History Exposed in Plain Text oodaloop.com
- ChatGPT for Mac could be hacked with just a few lines of code Mezha
- ChatGPT Mac App Vulnerability Exposed User Data to Hackers The Tech Buzz
Want the full story? Read the original reporting
Read on WIRED