Flaw in ChatGPT Mac App Exposed Sensitive Data and Chats
AI

Flaw in ChatGPT Mac App Exposed Sensitive Data and Chats

TechNews Editorial
TechNews EditorialOct 2, 2026 · 2 min read
Share

Why it matters

The flaw highlights how deep system access and trust required by AI tools can create security risks if vulnerabilities are left unpatched.

The facts

  • Researchers found a security flaw in the ChatGPT macOS app that could have exposed chat logs and browser sessions.
  • OpenAI acknowledged and fixed the vulnerability in its system change log on September 25.
  • The exploit was described as trivial and required only a dozen lines of code to bypass security checks.

Researchers at the Objective-See Foundation discovered a security vulnerability in the ChatGPT macOS application. The flaw could have allowed an attacker to take over ChatGPT on a target computer. This access included all stored chat logs, application data, and connected browser sessions.

Objective-See researchers detailed the flaw

Patrick Wardle, a software analyst and macOS researcher at the Objective-See Foundation, explained the system risks. AI platforms require deep system access and trust to function properly. Wardle compared these agents to building managers with keys to every room. If corrupted, unprivileged code gains access to restricted areas.

OpenAI acknowledged the security flaw and the applied fix in its system change log on September 25. Shane Bauer, an OpenAI spokesperson, stated that the company continues to evolve its security practices while recognizing a need to move faster.

Security checks were bypassed by attackers

The ChatGPT macOS app utilizes multiple components that communicate securely by checking digital signatures. These validity checks confirm that processes belong to OpenAI rather than outside malicious software. The system design requires signature checks at three layers of remove to block proxy attacks.

A software execution trace shows an untrusted script passing through three nested interpreter processes and entering the main application process.
Illustration: AI & Tech News

Objective-See Foundation researchers found that a trusted script interpreter accepted untrusted scripts. The interpreter could be manipulated to deliver scripts into the main ChatGPT process. Wardle noted that the malicious script simply spawned the script interpreter three times to satisfy parent and grandparent checks.

Wardle described the vulnerability as insanely trivial to exploit. His proof of concept required only about a dozen lines of code. Beyond chat logs, the flaw could force ChatGPT to run commands for attackers, including accessing browsers and sensitive applications under legitimate software instructions.

Read nextOpenAI Adds Virtual Try-On and Favorites to ChatGPT for Online Shopping

Artificial intelligence companies face pressure

Wardle plans to present analysis on AI macOS application bugs at the Objective by the Sea security conference in November. He recently found a patched flaw in Meta's Muse AI assistant dictation feature that could have exposed an authentication token. He also submitted a new vulnerability finding to OpenAI regarding the integration between ChatGPT and the new always on Dots AI assistant, which OpenAI is currently reviewing.

Wardle stated that artificial intelligence companies remain fixated on adding features. More features mean a broader attack surface, and security still often appears to be an afterthought.

Wardle will present his analysis at an Apple-focused security conference in November.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Keep reading