ChatGPT macOS App Flaw Exposed Sensitive Data to Hackers
A recently patched security flaw in OpenAI’s ChatGPT macOS application could have allowed attackers to seize all chat histories and execute arbitrary commands on a victim’s machine. The vulnerability, discovered by Objective‑See Foundation researcher Patrick Wardle, highlights how AI platforms’ deep system access makes them attractive targets for exploitation.

Critical Flaw Discovered in ChatGPT macOS App
According to WIRED, a recently patched vulnerability in OpenAI’s ChatGPT macOS application could have let attackers harvest all chat logs and run arbitrary commands on a victim’s machine. The bug was discovered by researchers at the Objective‑See Foundation, with software analyst and longtime macOS researcher Patrick Wardle leading the analysis. The flaw essentially allowed an attacker to take over ChatGPT on a compromised computer, granting access to the app’s stored chat histories, browser sessions, and other interconnected data.
How the Exploit Works
The vulnerability centered on a trusted script interpreter that accepted untrusted scripts or command lists. Attackers could spawn this interpreter three times, satisfying the parent‑and‑grandparent process checks that the system uses to verify legitimacy. By doing so, malicious code could be injected directly into the main ChatGPT process, bypassing the signature verification layers that are normally required at three levels of remove from the request. This gave the attacker not only read access to chat logs but also the ability to issue commands such as opening browsers or other sensitive applications, with those requests appearing as legitimate instructions from the OpenAI software itself.
OpenAI Acknowledges and Patches
OpenAI publicly acknowledged the security flaw in its system change log on September 25, noting the need to move faster on security practices. The company’s acknowledgment is documented in the acknowledged changelog, which details the fix and the broader effort to improve defensive measures. OpenAI spokesperson Shane Bauer told WIRED that the incident reinforced the importance of continuous security evolution as AI applications become more pervasive.
Broader Implications for AI Security
The discovery underscores a growing trend: AI software itself is becoming a prime target for attackers. Wardle recently found a flaw in Meta’s Muse AI assistant that could have let a local attacker capture a mishandled authentication token and gain access to user data. This found a flaw report highlights how even AI assistants can be compromised. Meanwhile, he has also reported a new vulnerability related to the integration between ChatGPT and OpenAI’s new always‑on Dots AI assistant, which is currently under review. The new always-on Dots link illustrates the expanding attack surface of always‑on agents, reinforcing the need for comprehensive security testing across the AI ecosystem.
Researcher’s Ongoing Work and Recommendations
Wardle will present a deeper analysis of several macOS AI application bugs at Objective by the Sea, an Apple‑focused security conference in November. His work continues to reveal how the deep system access granted to AI agents creates a tempting target for attackers. As AI companies race to add features, security must stay at the forefront, otherwise the broader attack surface will only grow. Wardle stresses that the industry’s current fixation on feature delivery often leaves security as an afterthought, a pattern that must change to protect users and data.
Sources
- WIREDA Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
Continue chronologically





