Researchers at the Objective-See Foundation discovered a security vulnerability in the ChatGPT macOS application. The flaw could have allowed an attacker to take over ChatGPT on a target computer. This access included all stored chat logs, application data, and connected browser sessions.
Objective-See researchers detailed the flaw
Patrick Wardle, a software analyst and macOS researcher at the Objective-See Foundation, explained the system risks. AI platforms require deep system access and trust to function properly. Wardle compared these agents to building managers with keys to every room. If corrupted, unprivileged code gains access to restricted areas.
OpenAI acknowledged the security flaw and the applied fix in its system change log on September 25. Shane Bauer, an OpenAI spokesperson, stated that the company continues to evolve its security practices while recognizing a need to move faster.
Security checks were bypassed by attackers
The ChatGPT macOS app utilizes multiple components that communicate securely by checking digital signatures. These validity checks confirm that processes belong to OpenAI rather than outside malicious software. The system design requires signature checks at three layers of remove to block proxy attacks.

Objective-See Foundation researchers found that a trusted script interpreter accepted untrusted scripts. The interpreter could be manipulated to deliver scripts into the main ChatGPT process. Wardle noted that the malicious script simply spawned the script interpreter three times to satisfy parent and grandparent checks.
Wardle described the vulnerability as insanely trivial to exploit. His proof of concept required only about a dozen lines of code. Beyond chat logs, the flaw could force ChatGPT to run commands for attackers, including accessing browsers and sensitive applications under legitimate software instructions.
Read nextOpenAI Adds Virtual Try-On and Favorites to ChatGPT for Online ShoppingArtificial intelligence companies face pressure
Wardle plans to present analysis on AI macOS application bugs at the Objective by the Sea security conference in November. He recently found a patched flaw in Meta's Muse AI assistant dictation feature that could have exposed an authentication token. He also submitted a new vulnerability finding to OpenAI regarding the integration between ChatGPT and the new always on Dots AI assistant, which OpenAI is currently reviewing.
Wardle stated that artificial intelligence companies remain fixated on adding features. More features mean a broader attack surface, and security still often appears to be an afterthought.
Wardle will present his analysis at an Apple-focused security conference in November.



