A recently patched vulnerability in the macOS version of OpenAI’s ChatGPT app could have allowed an attacker to take over ChatGPT on a victim’s computer and access chat logs, other data stored by the app, and connected browser sessions.
The vulnerability was discovered by researchers at the Objective-See Foundation. It shows how the broad system access and trust given to AI applications can also make them attractive targets for attackers.
OpenAI publicly acknowledged the security flaw and its fix in its system change log on September 25 (25/09).
ChatGPT Mac App Vulnerability Could Have Taken Over the App
The vulnerability could have been exploited to effectively take control of ChatGPT on a victim’s Mac.
An attacker could potentially access chat logs and other information stored by the application. The flaw could also allow ChatGPT to run commands for an attacker, including requests to access a browser or other sensitive applications.
The requests could appear to be legitimate instructions issued by OpenAI software.
The vulnerability was discovered by Patrick Wardle, a software analyst at the Objective-See Foundation and longtime macOS researcher.
“Agents need a lot of access to do their job,” Wardle said. “They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that’s super problematic. It can mean that unprivileged code could then potentially have access to all the things.”
Trusted ChatGPT Component Created Security Weakness
The ChatGPT macOS app has several components that communicate with each other using digital signature checks.
These checks are designed to confirm that the processes involved are OpenAI components rather than outside or potentially malicious software.
The system also checks signatures at three layers removed from the original request. This design is intended to prevent malicious software from directing an OpenAI component to act as a trusted proxy.
However, Objective-See Foundation researchers found a trusted component, a script interpreter, that could accept an untrusted script or list of commands and deliver it into the main ChatGPT process.
The researchers found that the security checks could be satisfied by having the malicious script repeatedly spawn the script interpreter before making the request.
“They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements,” Wardle said.
Vulnerability Required Malware on the Target Mac
The vulnerability could only be exploited by an attacker who already had malware installed on the target computer.
Despite this requirement, Wardle described the vulnerability as “insanely trivial” to exploit.
His proof of concept required about a dozen lines of code.
Once exploited, the flaw could provide access to ChatGPT chat logs and allow ChatGPT to execute commands for the attacker, including commands involving a browser or other sensitive applications.
OpenAI Acknowledged and Patched the Flaw
OpenAI publicly acknowledged the security vulnerability and its fix in its system change log on September 25.
“We continue to evolve our security practices, but recognize a need to move faster,” OpenAI spokesperson Shane Bauer told WIRED in a statement.
Wardle is scheduled to present an analysis of several AI macOS application bugs at Objective by the Sea, an Apple-focused security conference in November.
The researcher recently found another now-patched vulnerability in the dictation feature of Meta’s Muse AI assistant. That vulnerability could have been exploited by a local attacker to obtain a mishandled authentication token and gain access to user data.
Researcher Warns of Growing AI Attack Surface
Wardle said he has already submitted another vulnerability finding to OpenAI involving the integration between ChatGPT and the company’s new always-on Dots AI assistant.
OpenAI is currently reviewing the report.
“AI companies are fixated on adding features right now,” Wardle said. “But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought.”
PHOTO: UNSPLASH
This article was created with AI assistance.
We make every effort to ensure the accuracy of our content, some information may be incorrect or outdated. Please let us know of any corrections at [email protected]. //
Read More

Tuesday, 06-10-26
