ChatGPT’s Mac app had a hole that could have let a hacker read everything the app knew. The bug, found by researchers at the Objective-See Foundation, let an attacker take over the app and get at chat logs, browser sessions, and even run commands as if they were the app itself.
The Bug’s Reach
The flaw, patched since September 25, sat in a trusted script interpreter inside the app. That interpreter took commands from elsewhere and ran them inside the main ChatGPT process. A hacker could set up the interpreter to run a script three times, meeting the app’s checks on parent and grandparent processes along the way.
Patrick Wardle, a software analyst at Objective-See, says the problem was simple to exploit. His proof of concept needed only about a dozen lines of code. Once in, an attacker could:
- Read chat logs
- Access browser sessions
- Run commands that appeared to come from the app itself
- Target other sensitive applications on the victim’s machine
How the Checks Were Broken
ChatGPT’s macOS app uses digital signatures to check that processes talking to each other are truly OpenAI components, not something pretending to be one. The system design goes three layers deep to guard against a malicious script setting up an OpenAI component as a proxy.
Wardle found that one trusted component, a script interpreter, would accept an untrusted script or command list. By spawning the interpreter three times, a malicious script could meet the app’s parent and grandparent checks and pass through anyway.
What OpenAI Said
OpenAI publicly acknowledged the flaw and fix in its system change log on September 25. A spokesperson, Shane Bauer, told WIRED in a statement: “We continue to evolve our security practices, but recognize a need to move faster.”
More Than One Hole
Wardle has a history of finding problems in AI apps. He recently found a flaw in Meta’s new Muse AI assistant, which could have let a local attacker grab a mishandled authentication token and access user data. That bug is now patched.
He has also submitted a new vulnerability finding to OpenAI about the integration between ChatGPT and the company’s new always-on Dots AI assistant. OpenAI is currently reviewing that report.
The Pattern Is Worrying
Wardle says AI companies are focused on adding features right now. But more features mean a bigger attack surface. He argues that security remains an afterthought for many of these firms.
“AI companies are fixated on adding features right now,” Wardle says. “But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought.”
The Conference
Wardle will present analysis of a number of AI macOS application bugs at Objective by the Sea, an Apple-focused security conference in November.
What This Means for Users
The flaw shows how much trust we give AI software on our computers. ChatGPT runs with deep system access to do its job, and that access creates a target.
The patch is out, but the lesson is not. As AI apps grow more common, the risk grows too.
Key Facts Box
- Patch acknowledged: September 25
- Bug discovered by: Objective-See Foundation
- Proof of concept lines: About a dozen
- Spoken by: Shane Bauer, OpenAI spokesperson
- Conference: Objective by the Sea, November
The story is a warning about the pace of AI development. Companies are rushing to add features, and security is often left behind. That is a pattern worth watching, not just for ChatGPT but for every AI app that asks for deep access to a user’s device.
The fix is here, but the question of whether companies will slow down and secure their systems first is still open.
Source material: “A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data,” WIRED.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

