ChatGPT Mac App Had Bug That Exposed User Data

Original: A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

Why This Matters

As AI apps gain deep system access to power agents, they become high-value targets — and easy ones.

Objective-See Foundation researchers found a now-patched vulnerability in OpenAI's ChatGPT macOS app that could let attackers hijack the app, access all chat logs, and issue commands via browser or other apps. OpenAI acknowledged the fix in its changelog on September 25.

Researchers at the Objective-See Foundation discovered a vulnerability in the macOS version of ChatGPT that could allow an attacker to effectively take over the app on a victim's machine. The bug gave access to stored chat logs, browser sessions, and any apps connected to ChatGPT's agent features.

The ChatGPT macOS app is designed to verify digital signatures across three layers of process hierarchy — checking not just the requesting process, but its parent and grandparent — to block untrusted software from spoofing legitimate OpenAI components. However, researchers found a trusted script interpreter within the app that would accept unsigned scripts. By spawning the interpreter three times in a chain, an attacker's malicious script could satisfy all three signature checks and inject itself into the main ChatGPT process.

Researcher Patrick Wardle called the exploit 'insanely trivial,' requiring roughly a dozen lines of code. Once inside, an attacker could read all chat history or issue commands — such as launching a browser — that would appear to originate from OpenAI's own software.

OpenAI acknowledged the flaw in its system changelog on September 25. Spokesperson Shane Bauer told WIRED: 'We continue to evolve our security practices, but recognize a need to move faster.' Wardle plans to present findings on multiple AI macOS app vulnerabilities at the Objective by the Sea security conference in November.

Source

wired.com — Read original →