# ChatGPT Mac app flaw could have let hackers grab chat logs

Digest AI · Society & Work · published 2026-10-02T09:45:00Z

Canonical: https://digestai.news/story/chatgpt-mac-app-flaw-could-have-let-hackers-grab-chat-logs

## Summary

Researchers at the Objective-See Foundation discovered a security vulnerability in the ChatGPT macOS application that could have allowed attackers to access sensitive user data. The flaw involved a trusted script interpreter that accepted untrusted scripts, enabling malicious code to bypass the app’s multi-layered digital signature checks. By spawning the interpreter three times, an attacker could inject commands into the main ChatGPT process, granting access to chat logs and potentially controlling browser sessions or other applications.

Patrick Wardle, a software analyst at Objective-See, described the exploit as "insanely trivial," noting that his proof of concept required only about a dozen lines of code. OpenAI acknowledged the issue and released a fix on September 25. A spokesperson, Shane Bauer, stated that the company recognizes the need to move faster on security practices. Wardle highlighted the broader risk posed by AI agents, which require deep system access to function, creating a significant attack surface if compromised.

Wardle plans to present this and other AI-related macOS security findings at the Objective by the Sea conference in November. He also recently identified a patched flaw in Meta’s Muse AI assistant and has submitted a new vulnerability report regarding OpenAI’s Dots AI assistant integration, which is currently under review. The incident underscores the tension between rapid feature development and robust security in AI platforms.

## Key points

- Objective-See researchers found a flaw in ChatGPT's Mac app allowing access to chat logs and browser sessions.
- OpenAI acknowledged the bug and released a fix on September 25, citing a need to move faster on security.
- Patrick Wardle noted the exploit was trivial, requiring only about a dozen lines of code to execute.

## Why it matters

This vulnerability highlights the significant security risks associated with granting AI agents deep system access. It serves as a warning that rapid feature development in AI platforms can outpace security measures, potentially exposing user data to sophisticated attacks.

## Sources

1. [A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data](https://wired.com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-data) (Wired AI, 2026-10-02)

## Cite

Digest AI, "ChatGPT Mac app flaw could have let hackers grab chat logs", 2 October 2026, https://digestai.news/story/chatgpt-mac-app-flaw-could-have-let-hackers-grab-chat-logs

---

Written by Digest AI's editorial model from the linked sources; the sources are the record. Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse
JSON: https://digestai.news/story/chatgpt-mac-app-flaw-could-have-let-hackers-grab-chat-logs.json
