A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

Researchers at the Objective-See Foundation discovered a security vulnerability in the ChatGPT macOS app that could have allowed attackers to bypass signature checks and access sensitive user data. OpenAI has since acknowledged the flaw and implemented a fix to prevent malicious scripts from manipulating the application's internal processes.
Why it matters
As AI platforms gain deeper system access, they become high-value targets for cyberattacks, necessitating more rigorous security protocols.
The bug could have been exploited to essentially take over ChatGPT on a victim’s computer, giving an attacker access to all the chat logs and other data stored by the app, as well as interconnections like browser sessions. Discovered by researchers at the Objective-See Foundation, the vulnerability illustrates the deep system access and trust that AI platforms are afforded in order to work—and the target that this puts on their backs.
“Agents need a lot of access to do their job,” says Objective-See Foundation software analyst and longtime macOS researcher Patrick Wardle. “They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that’s super problematic. It can mean that unprivileged code could then potentially have access to all the things.”
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in