A recently patched vulnerability in the macOS version of ChatGPT could have allowed malware already present on a computer to hijack the trusted AI application and reach sensitive information. The weakness was discovered by researchers at the nonprofit Objective-See Foundation and detailed in an October 2 report by WIRED.
The prerequisite is important: this was not described as a remote attack that could compromise any Mac simply because ChatGPT was installed. According to WIRED, an attacker first needed to have malware running on the target machine. From there, however, the flaw could have let that otherwise untrusted code operate through ChatGPT’s privileges and connections.
The ChatGPT Mac app uses multiple components that authenticate one another with digital-signature checks. Those checks are intended to verify that a request is moving between genuine OpenAI processes rather than coming from malicious software. The design also examined the requesting process’s parent and grandparent, adding layers meant to prevent an OpenAI component from being used as a proxy.
Objective-See researchers found a weakness in a trusted script-interpreter component. WIRED reported that the interpreter would accept an untrusted script and could then be manipulated to pass commands into the main ChatGPT process. Researcher Patrick Wardle said the checks could be satisfied by launching the interpreter repeatedly so that the apparent process ancestry looked trusted.
Wardle characterized the exploit as straightforward and said his proof of concept required roughly a dozen lines of code. The potential impact went beyond reading locally stored ChatGPT conversations. The report says an attacker could have used the compromised app to issue commands involving connected browser sessions or other sensitive applications, with the activity appearing to originate from legitimate OpenAI software.
OpenAI publicly acknowledged the vulnerability and its fix in a September 25 system changelog, according to WIRED. A company spokesperson told the publication that OpenAI is continuing to improve its security practices while recognizing that it needs to move more quickly. The report did not say that the flaw had been exploited against users in the wild.
The case illustrates a broader security tension around desktop AI. Agents and assistants become more useful when they can interact with browsers, files, messages, and other applications, but each trusted connection can also increase the damage possible if the AI software itself is subverted. That conclusion is an inference from the access and attack path described by WIRED, not evidence that every connected AI app is vulnerable in the same way.
Wardle plans to present research on multiple macOS AI-application bugs at the Objective by the Sea security conference in November. WIRED also reported that he has submitted another finding to OpenAI concerning the integration between ChatGPT and the company’s always-on Dots assistant; OpenAI is reviewing that separate report, and its validity and impact remain unresolved.