A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

Staff
By Staff 10 Min Read

It is easy to open the news and feel like artificial intelligence has become a kind of digital wild west. Hardly a day passes without a story about AI agents autonomously hacking websites, cybercriminals using AI chatbots to craft phishing emails, or scammers deploying deepfakes to trick unsuspecting people. But there is a quieter, perhaps more unsettling story developing in the background. Security researchers are increasingly pointing out that the AI tools we install on our own devices are becoming valuable targets in their own right. Recently, a serious vulnerability was discovered and patched in the macOS version of OpenAI’s ChatGPT. If exploited, this bug could have allowed an attacker to essentially take over ChatGPT on a victim’s computer, gaining access to chat logs, stored data, and even connected services like browser sessions. The discovery was made by researchers at the Objective-See Foundation, a security research group known for digging into Apple’s ecosystem. Their findings reveal something deeper than a simple software glitch: they highlight the enormous level of trust and system access that modern AI platforms are given in order to function, and they suggest that this trust is exactly what makes these platforms so attractive to attackers.

The whole situation can feel abstract until you think about what an AI assistant actually does on your computer. Unlike a simple calculator or a basic text editor, a modern AI app like ChatGPT is constantly juggling sensitive functions. It may read your screen, manage clipboard contents, interact with your browser, access files, and even take actions on your behalf. To pull all of that off, it needs a surprisingly broad set of permissions. Patrick Wardle, a longtime macOS researcher and software analyst at the Objective-See Foundation, put it in a way that makes perfect sense. He compared AI agents to a building manager who carries the keys to every single room in the building. That level of access is necessary for the job, but it also creates a massive risk. If someone can corrupt or subvert that building manager, if they can impersonate them or trick them into doing the wrong thing, then all of those rooms become open to someone who should not be there. Wardle warned that this kind of subversion is “super problematic” because unprivileged code on the system could suddenly gain access to all sorts of sensitive information and powerful capabilities that should have been completely off limits.

To understand how the vulnerability worked, it helps to know a little bit about how the ChatGPT macOS app is structured. The app is built from multiple components that need to communicate with each other securely. To make sure that the right parts are talking to the right parts, the system uses digital signature checks. These checks are meant to confirm that each process interacting with ChatGPT is a genuine OpenAI component, not some malicious outside program trying to sneak in a request. The designers went even further, requiring these signature checks at three different levels of trust. It was a thoughtful security measure, the kind of defense-in-depth approach that makes sense when you are dealing with an app that has access to so much personal data. But the researchers at Objective-See found a clever way around it. They realized that there was a trusted component, a script interpreter, which would accept an untrusted script containing commands to run. From there, the malicious script could be manipulated and delivered straight into the main ChatGPT process. The system checked the parent and grandparent of that process as part of its security model, but the attacker could simply have the malicious script spawn the script interpreter three times in a row, creating a chain of supposedly trusted processes. That satisfied the check, even though the actual request was anything but trustworthy. Wardle described it as “insanely trivial” to exploit, and his proof of concept required only about a dozen lines of code.

The trivial nature of this exploit is worth pausing over because it shows how fragile the trust can be, even in a system that was deliberately designed with layered defenses. In many ways, the exploit was like walking up to the same security guard three times, showing a badge, and then slipping through the door once he was used to seeing the same familiar face. The check was there, and it was not maliciously defeated in some complex cryptographic way. It was simply tricked by a clever bit of process-spawning logic. The consequences of that trick were significant. An attacker who took advantage of this flaw could not only read a victim’s ChatGPT chat logs, which may contain personal questions, work documents, medical inquiries, or business secrets, but they could also get ChatGPT to run commands for them. Since those commands would appear to originate from legitimate OpenAI software, they could use the app’s powerful access to interact with a browser or other sensitive applications on the machine. In other words, a malicious actor could hijack the AI’s privileges to carry out their own instructions, making it look like the AI assistant was simply doing what it normally does. That kind of hidden manipulation is particularly frightening because there may be no obvious sign that anything is wrong until it is far too late.

The discovery also points to a broader issue that is only going to become more urgent as AI tools become even more integrated into our daily lives. These apps are not just passive chatbots anymore. They are evolving into agents that can perform tasks, manage schedules, interact with other software, and make decisions. That means they are accumulating more and more sensitive data, and they are gaining deeper access to our digital lives. At the same time, they are becoming a juicier target for cybercriminals, scammers, and nation-state actors. OpenAI publicly acknowledged the flaw and the fix in its system change log on September 25. In a statement to WIRED, OpenAI spokesperson Shane Bauer said, “We continue to evolve our security practices, but recognize a need to move faster.” That admission is telling. It suggests that security is still playing catch-up in the AI industry, where the pressure to ship useful and impressive features often outpaces the slow, methodical work of securing them. It is also a reminder that security researchers like the team at Objective-See play an absolutely vital role. They are the ones who find these hidden flaws before criminals can take advantage of them, and their work often goes unnoticed by the general public.

None of this is meant to suggest that you should immediately delete ChatGPT from your computer or panic about the future of AI. The vulnerability was patched, and there is no evidence that it was ever exploited in the wild. But this incident should encourage all of us to think more carefully about the tools we invite into our digital lives. When you install an AI assistant and grant it permissions to read, write, and act on your behalf, you are essentially handing over a great deal of power. You are hiring that building manager and trusting them with every key. It is sensible to demand transparency and security from the companies that make these tools, and it is reasonable to ask how they are testing their own software, whether they are working with independent security researchers, and how quickly they respond when problems are discovered. We should also remember that security is never a one-time fix. It is a constant process of finding weak spots, patching them, and then looking for the next weak spot. The ChatGPT vulnerability is not a reason to give up on AI, but it is a good reason to stay informed, keep your software updated, and appreciate the security researchers who work behind the scenes to keep our digital world from falling apart. As AI continues to move further into every corner of our lives, we will need that same careful balance of enthusiasm, caution, and humility, because the promise of artificial intelligence is enormous, but so is the responsibility that comes with it.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *