ChatGPT Mac App Flaw Exposed Deep System Access Risks

2 min read
Source: WIRED
ChatGPT Mac App Flaw Exposed Deep System Access Risks
Photo: WIRED
TL;DR

A critical vulnerability in the macOS version of ChatGPT, discovered by Objective-See Foundation researchers, could have allowed attackers to access sensitive user data and execute commands. The flaw, which required only about ten lines of code to exploit, was patched by OpenAI on September 25, 2026. It highlighted the security risks of granting AI agents broad system permissions.

Key points

  • Objective-See Foundation identified a flaw in ChatGPT’s macOS app that bypassed digital signature checks.
  • The vulnerability allowed attackers to access chat logs, browser sessions, and other sensitive data.
  • OpenAI acknowledged and patched the issue on September 25, 2026.
  • The exploit required pre-existing malware on the victim’s machine but was described as 'insanely trivial' to execute.
  • Researchers noted that AI agents’ broad system access creates significant security risks.

Background

This incident follows a trend of expanding AI agent capabilities on macOS, including recent integrations with Apple Messages and writing style features that require broad permissions. Previous coverage noted concerns about AI accessing sensitive data, such as work emails and personal messages, raising questions about the security implications of deep system integration.

How outlets are covering it

WIRED and Mezha both reported on the vulnerability, emphasizing the ease of exploitation and the risks of AI agents having broad system access. WIRED highlighted the 'insanely trivial' nature of the exploit and OpenAI’s acknowledgment of the need for faster security responses. Mezha focused on the technical details of the bypass and the broader implications for AI security. Both sources cited Patrick Wardle of Objective-See Foundation, who criticized AI companies for prioritizing features over security.

Why it matters

The vulnerability underscores the security risks of granting AI agents deep system access, potentially exposing sensitive user data to attackers. It highlights the need for robust security measures in AI applications and the importance of balancing feature development with security concerns.

What to watch

OpenAI has patched the vulnerability, but researchers are continuing to identify and report new issues, including a recent finding related to ChatGPT’s integration with the Dots AI assistant. The broader industry is expected to face increased scrutiny on security practices as AI agents become more prevalent.

Share this article

Want the full story? Read the original reporting

Read on WIRED