OpenAI patches ChatGPT macOS flaw that exposed chat logs

This digest was compiled by AI from multiple sources — links to the originals are below.
OpenAI patched a vulnerability in its ChatGPT macOS app that could have let attackers take over the application and access chat logs and other stored data. The flaw was discovered by researchers at the Objective-See Foundation and fixed on September 25. The bug could also have allowed attackers to issue commands through ChatGPT to access a victim's browser or other sensitive applications.
Key Facts
- OpenAI fixed the vulnerability on September 25, 2026, according to its system change log.
- Objective-See Foundation researcher Patrick Wardle said the exploit required about a dozen lines of code.
- The flaw could have allowed an attacker to access ChatGPT chat logs and other data stored by the app.
- Wardle will present analysis of AI macOS application bugs at the Objective by the Sea conference in November.
Vulnerability Discovery
Researchers at the Objective-See Foundation discovered the vulnerability in the macOS version of OpenAI's ChatGPT. The flaw allowed an untrusted script to be passed into the main ChatGPT process through a trusted script interpreter. Patrick Wardle, a software analyst at Objective-See Foundation, described the exploit as 'insanely trivial' and said his proof of concept required only about a dozen lines of code. The bypass involved launching the script interpreter three times to satisfy the app's process ancestry checks.
Security Implications
The vulnerability could have given an attacker access to all chat logs and other data stored by the ChatGPT app. An attacker could also have used ChatGPT to run commands that accessed a victim's browser or other sensitive applications. OpenAI spokesperson Shane Bauer said the company continues to evolve its security practices but recognizes a need to move faster. Wardle noted that AI agents require extensive system access, making them a high-value target if corrupted.
OpenAI Response
OpenAI publicly acknowledged the security flaw and fix in its system change log on September 25. The ChatGPT macOS app includes multiple components that communicate securely by checking digital signatures. The system requires signature checks at three layers of remove from a request to prevent malicious proxy use. Wardle will present analysis of several AI macOS application bugs at the Objective by the Sea security conference in November.