ChatGPT Mac Flaw Let Hackers Steal Chat Logs — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- ChatGPT's macOS app contained a vulnerability that researchers said could give attackers access to all stored chat logs, browser sessions, and other sensitive data on a victim's machine, with the ability to trick ChatGPT into executing commands that appeared to originate from legitimate OpenAI software.
- Objective-See Foundation researcher Patrick Wardle discovered that ChatGPT's security relied on three layers of digital signature checks, but found a trusted script interpreter component would accept an untrusted script; the malicious script simply spawned the interpreter three times to satisfy the checks.
- OpenAI acknowledged the flaw and fix in its system change log, and told WIRED it 'recognize[s] a need to move faster' on security, according to spokesperson Shane Bauer.
- Wardle described the exploit as 'insanely trivial,' requiring only about a dozen lines of code in his proof of concept, though it required an attacker to already have malware on the target machine.
- Wardle will present analysis of multiple AI macOS app bugs at the Objective by the Sea security conference in November, and said he has already reported a separate flaw related to the integration between ChatGPT and OpenAI's new always-on Dots AI assistant.
- Meta's Muse AI assistant recently had a similar dictation-feature vulnerability patched that Wardle found, which could have let a local attacker grab an authentication token and access user data—part of what Wardle called an industry pattern in which 'security... still often seems like an afterthought.'
Why it matters: AI desktop apps like ChatGPT require deep system-level access to function, turning them into high-value targets: a single flaw exposes not just chat content but browser sessions and credentials. Wardle's proof of concept needed about a dozen lines of code to bypass OpenAI's three-layer signature check, and his parallel discovery of a similar bug there—and a patched one in Meta's Muse—suggests the risk is systemic across AI companies racing to ship features rather than harden security.
Ask SkimNews



