A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting—and vulnerable—target.
A critical flaw within the ChatGPT Mac app has the potential to expose sensitive user data to hackers, researchers have uncovered. Objective-See Foundation analysts discovered the vulnerability, which could enable malicious actors to take control of the AI platform on a victim's computer, gaining access to chat logs and other stored information.
Patrick Wardle, a software analyst and macOS expert from Objective-See Foundation, explained that the AI platforms are given extensive system access and trust due to their functionality, leaving them as prime targets for potential exploitation.
OpenAI acknowledged the security flaw and addressed it in their system change log on September 25. The ChatGPT Mac app incorporates various components that communicate securely through digital signature checks to verify the legitimacy of processes. However, the researchers found a trusted component, a script interpreter, that could accept untrusted scripts and manipulate them to gain control of the main ChatGPT process.
This vulnerability was relatively easy to exploit, requiring only around a dozen lines of code. Wardle demonstrated that the flaw could lead to accessing ChatGPT chat logs, executing commands, including accessing other sensitive applications like browsers, all while appearing as legitimate OpenAI software requests.
Wardle will present his analysis of AI macOS app bugs at the Objective by the Sea security conference in November. He has also recently found and reported a vulnerability in Meta's Muse AI assistant. OpenAI is currently reviewing his report on the ChatGPT Mac app vulnerability. As AI companies continue to expand their features, Wardle emphasizes the importance of prioritizing security measures to mitigate potential risks.
Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.