AIToday
Large Language ModelsWIRED AIPublished: Oct 2, 2026, 19:00 JST

Objective-See Found Flaw Let Attackers Take Over ChatGPT Mac App

Objective-See Found Flaw Let Attackers Take Over ChatGPT Mac App

3 Key Points

  1. What happened

    Researchers at the Objective-See Foundation found a now-patched bug in the macOS ChatGPT app that could take over ChatGPT on a victim's computer, exposing chat logs, browser sessions and other stored data. OpenAI logged the flaw and fix on September 25.

  2. Why it matters

    The bug shows how much system access AI apps like ChatGPT get to work at all, so a small security slip there could expose a user's chats and connected sessions, not just one feature.

  3. What to watch

    Patrick Wardle says he has submitted another ChatGPT-related finding, tied to OpenAI's Dots assistant, and OpenAI is reviewing it; he presents his AI macOS bug analysis at Objective by the Sea in November.

WHO IT HITSPeople who use the macOS ChatGPT app on their work machines, and the security and IT teams who approve and manage such AI tools on employee laptops, are the ones most directly affected, since the flaw could have exposed both chat logs and browser sessions on a device.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The finding came from the Objective-See Foundation, a group focused on Apple security, and its analyst Patrick Wardle says the vulnerability was "insanely trivial" to exploit. The design of the macOS ChatGPT app depends on digital signatures checked at three layers of remove from a request, so that a component can only act on behalf of trusted OpenAI software. Wardle's team showed that a trusted script interpreter could accept an untrusted script, and that spawning it three times let the malicious script satisfy those validity checks and reach the main ChatGPT process, which is why the gap mattered out of proportion to its size.

Wardle has been looking at several AI macOS applications, not only ChatGPT. He recently found a flaw, now patched, in the dictation feature of Meta's new Muse AI assistant that could have let a local attacker grab a mishandled authentication token and reach user data. He also says he has submitted a new vulnerability finding to OpenAI related to the link between ChatGPT and the company's new always-on Dots AI assistant, which OpenAI is reviewing.

The timing of this disclosure matters because AI assistants are being granted broad reach into everyday machines to function. Wardle's view, that security is often an afterthought as companies rush features out, suggests the test of these platforms may be less about how fast they patch one bug and more about whether security keeps pace as their access grows. That reading is Wardle's, not a measured industry trend.

FAQ
How easy was the ChatGPT bug to exploit?
Objective-See Foundation's Patrick Wardle called it "insanely trivial" and said his proof of concept needed only about a dozen lines of code. A malicious script could spawn the script interpreter three times to satisfy ChatGPT's signature checks.
What could an attacker have gotten access to?
The bug could have taken over ChatGPT on a victim's computer, giving access to all chat logs and other data the app stores, as well as interconnections like browser sessions. It could also make ChatGPT run commands for the attacker.
What did OpenAI say about the fix?
OpenAI acknowledged the security flaw and fix in its system change log on September 25. Spokesperson Shane Bauer told WIRED, "We continue to evolve our security practices, but recognize a need to move faster."

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleAlphaGo engineer leaves Google DeepMind, says LLMs don't reason