ChatGPT Mac Bug Gave Attackers Access to User Data — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- The ChatGPT macOS app vulnerability could have been exploited to take over the application, giving attackers access to all chat logs, browser sessions, and other data stored by the app, plus the ability to run commands through ChatGPT as if issued by the user
- Objective-See Foundation researchers found the bug exploited a trusted script interpreter component that accepted untrusted scripts while satisfying the app's multi-layer digital signature checks, which verify parent and grandparent processes
- OpenAI publicly acknowledged the flaw and fix in its system change log on September 25, with spokesperson Shane Bauer telling WIRED: "We continue to evolve our security practices, but recognize a need to move faster"
- Patrick Wardle called the vulnerability "insanely trivial" to exploit, saying his proof of concept required only about a dozen lines of code
- OpenAI is now reviewing a separate vulnerability report Wardle submitted about ChatGPT's integration with the company's new always-on Dots AI assistant
- Wardle said "AI companies are fixated on adding features right now" and warned that with each new feature the attack surface broadens while security "still often seems like an afterthought"
Why it matters: AI agents require deep system access to function, making their host apps high-value targets: this bug let unprivileged code hijack a trusted OpenAI process and access every chat log, browser session, and command on the user's machine. OpenAI publicly acknowledged the September 25 fix but admitted it 'recognize[s] a need to move faster' as the same researcher found a related ChatGPT-Dots flaw and a separate Meta Muse vulnerability still being patched across the industry.
Ask SkimNews



