- Objective-See researchers found a ChatGPT Mac app flaw that could let an attacker take over the app. OpenAI patched it. Wired does not report any attacks in the wild.
- It matters because AI apps hold broad access to chats, browser sessions and other apps, so one weak internal check can expose a lot.
- Leaders should list AI desktop apps on company Macs, review what each can reach, confirm the patched version, and vet optional features before enabling them.
An AI assistant that can read your files, your browser and your messages is only as safe as its weakest internal door. A recently patched flaw in the ChatGPT app for macOS shows how that door can fail. The lesson here is simple: when software is given the keys to everything, the checks around those keys matter more than the features built on top.
What the researchers found
Researchers at the Objective-See Foundation found the flaw, according to Wired's reporting. It could have let an attacker take over ChatGPT on a victim's Mac. That would expose the chat logs and other data the app stores, plus connections such as browser sessions.
The attacker could also have made ChatGPT run commands, such as reaching a browser or other sensitive applications. Those requests would look like legitimate instructions from OpenAI's own software. Wired does not report any attacks in the wild.
OpenAI acknowledged the flaw and the fix in its change log on September 25. Spokesperson Shane Bauer told Wired: "We continue to evolve our security practices, but recognize a need to move faster."
How the checks were bypassed
The ChatGPT Mac app is built from several parts that talk to each other. Each part checks the other's digital signature, a kind of tamper-proof ID. The aim is to confirm that a request comes from OpenAI code and not from outside software.
The design goes further. It checks the sender, then its parent process, then its grandparent. This is meant to stop a malicious program from tricking a trusted one into passing on a request.
The researchers found a gap. One trusted component, a script interpreter, would accept an untrusted script and could be manipulated into delivering it to the main ChatGPT process. Researcher Patrick Wardle explained the trick: the malicious script starts the interpreter three times, then makes the request. That way, every layer of the check is satisfied.
Think of a mailroom clerk with a valid badge. The guard checks the clerk, the clerk's manager and the manager's manager. All three are genuine. But the clerk will carry any envelope handed to him, so the checks prove who is delivering, not what is inside.
Wardle called the flaw "insanely trivial" to exploit.
Why broad access raises the stakes
Wardle's own comparison is a building manager who holds the keys to every room. If the manager is subverted, unprivileged code may reach everything. That is the point for executives: an AI app is valuable to attackers because of how much it is allowed to touch.
OpenAI's change log shows how much that can be. A plugin lets the Mac app search through Messages conversations and send texts. Computer History is opt-in, and once enabled it gives ChatGPT and Codex a record of what a user did in the apps and sites they chose. Appshots let a user hand ChatGPT an image and the readable text of whichever window is in front.
These features are not reported to be affected by this flaw. Wired describes the exposure as chat logs, stored data, browser sessions and command execution. But the change log shows the direction of travel: more access, more connections, more to protect.
Wardle says AI companies are "fixated on adding features" and that security often seems like an afterthought. That is his assessment. Wired adds that he found a now-patched flaw in Meta's Muse assistant and has submitted a new finding on ChatGPT's link to OpenAI's Dots assistant, which OpenAI is reviewing. Two disclosed cases and one pending report are not proof of an industry pattern. They do justify asking questions.
What leaders should ask their teams
First, ask for a list of AI desktop apps on company Macs. Include the ones staff installed themselves.
Second, ask what each app can reach: browser sessions, messages, files, other apps. Treat each as privileged software, not a productivity add-on.
Third, ask that these apps are updated to the patched release. Ask OpenAI which version contains the fix, since the reporting does not say.
Fourth, review optional features before switching them on. OpenAI's change log says Business and Enterprise administrators must enable Computer History before staff can turn it on. That is a real decision point.
Last, ask vendors how they test the checks between their own components. Signatures prove who is asking. They do not prove the request is safe.
An assistant with a master key is a bigger target than the lock on any one door.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: OpenAI.





