
Flaw in ChatGPT's macOS App Could Have Let Attackers Grab Sensitive User Data
Researchers at the Objective-See Foundation found a flaw in ChatGPT's macOS app that could have let an attacker take over the app and reach chat logs, stored data, and browser sessions. OpenAI confirmed the fix on September 25.
OpenAI has patched a security flaw in its ChatGPT app for macOS that could have let an attacker take over the assistant on a victim's Mac and reach the app's chat logs, stored data, and browser sessions. Researchers at the Objective-See Foundation found the bug.
What the researchers found
Components of the ChatGPT macOS app verify each other with digital signature checks, so an instruction is honored only if it comes from an OpenAI process and not from outside, potentially malicious software. The checks reach three layers back from the request, so malicious code cannot direct a trusted component to act as its proxy.
The researchers found that one trusted component, a script interpreter, would accept an untrusted script and could be manipulated into passing it into the main ChatGPT process. "They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements," Wardle says.
What an attacker could have done
Wardle calls the exploit "insanely trivial": his proof of concept took about a dozen lines of code. Beyond reading the app's chat logs, the flaw could have made ChatGPT run commands for the attacker, such as reaching into a browser or another sensitive application, with those requests appearing to be legitimate instructions from OpenAI's own software.
OpenAI's response
OpenAI publicly acknowledged the flaw and the fix in a system changelog entry on September 25. "We continue to evolve our security practices, but recognize a need to move faster," OpenAI spokesperson Shane Bauer told WIRED.
Why it matters
The case shows what AI software itself is worth to attackers: these apps need deep system access to work, which makes them inviting targets. "Agents need a lot of access to do their job," Wardle says. "They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that's super problematic. It can mean that unprivileged code could then potentially have access to all the things."
Wardle will present analysis of several AI macOS application bugs at Objective by the Sea, an Apple-focused security conference, in November. He recently found a now-patched flaw in the dictation feature of Meta's new Muse AI assistant that a local attacker could have used to grab a mishandled authentication token and reach user data. He has also sent OpenAI a new report about the integration between ChatGPT and its new always-on Dots assistant; the company is reviewing it.
"AI companies are fixated on adding features right now," Wardle says. "But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought."
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.