ChatGPT macOS flaw exposed a route to stored data and commands
Objective-See Foundation researchers found a vulnerability that could let an attacker with local code access take over the app. OpenAI says it has been fixed.

A vulnerability in OpenAI’s macOS ChatGPT app could have allowed an attacker able to run code locally to take over the app, access stored chat logs and other data, or issue commands through trusted OpenAI software. The source report does not say the flaw was exploited or how many users may have been affected.
Researchers at the Objective-See Foundation found that a trusted script interpreter could pass an untrusted script into ChatGPT’s main process. That could bypass checks intended to verify component signatures and process ancestry.
Researcher Patrick Wardle said his proof of concept required about a dozen lines of code. The potential impact included requests to access a browser or other sensitive applications that would appear to come from OpenAI software.
OpenAI acknowledged the vulnerability and a fix in a system change log on 25 September. Spokesperson Shane Bauer said the company recognises it needs to move faster on security practices. The change log acknowledgement did not specify the fix’s technical details.
Wardle said he had separately submitted a report to OpenAI concerning ChatGPT’s integration with Dots AI. The company was reviewing that report; it is distinct from the patched macOS flaw.


