ChatGPT Mac app flaw could have let hackers grab chat logs
Researchers at the Objective-See Foundation discovered a security vulnerability in the ChatGPT macOS application that could have allowed attackers to access sensitive user data. The flaw involved a trusted script interpreter that accepted untrusted scripts, enabling malicious code to bypass the app’s multi-layered digital signature checks. By spawning the interpreter three times, an attacker…
Key points
- Objective-See researchers found a flaw in ChatGPT's Mac app allowing access to chat logs and browser sessions.
- OpenAI acknowledged the bug and released a fix on September 25, citing a need to move faster on security.
- Patrick Wardle noted the exploit was trivial, requiring only about a dozen lines of code to execute.
Patrick Wardle, a software analyst at Objective-See, described the exploit as "insanely trivial," noting that his proof of concept required only about a dozen lines of code. OpenAI acknowledged the issue and released a fix on September 25. A spokesperson, Shane Bauer, stated that the company recognizes the need to move faster on security practices. Wardle highlighted the broader risk posed by AI agents, which require deep system access to function, creating a significant attack surface if compromised.
Wardle plans to present this and other AI-related macOS security findings at the Objective by the Sea conference in November. He also recently identified a patched flaw in Meta’s Muse AI assistant and has submitted a new vulnerability report regarding OpenAI’s Dots AI assistant integration, which is currently under review. The incident underscores the tension between rapid feature development and robust security in AI platforms.
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Society & Work
All →- Microsoft Ireland says AI is now core to talent retention · 1 src
- OpenAI parts ways with three researchers for allegedly sharing sensitive information with an AI safety organization · 4 src
- Google adds Guided Vision to Gemini Live for blind users · 2 src
- OpenAI publishes essay arguing AI may excel at repetitive tasks · 1 src
- IBM study finds 60% of employees fear AI eroding critical thinking skills · 1 src
Comments
via GitHub Discussions