ChatGPT macOS app flaw could have let malware take over the app

ChatGPT macOS app flaw could have let malware take over the app

Researchers at the Objective-See Foundation found a vulnerability in the macOS version of OpenAI's ChatGPT app, WIRED reports. Exploited, it could have essentially taken over ChatGPT on a victim's computer, giving an attacker access to all the chat logs and other data the app stores, as well as interconnections like browser sessions. The flaw has since been patched, and OpenAI acknowledged the flaw and the fix in its system change log on September 25. OpenAI spokesperson Shane Bauer told WIRED in a statement: "We continue to evolve our security practices, but recognize a need to move faster."

The app is built from several components that talk to each other and verify one another's digital signatures. The point is to confirm that both sides of a request are OpenAI components, not outside, potentially malicious software. The design goes further and requires these signature checks at three layers of remove from the request, so that malware cannot make a seemingly trusted request by using an OpenAI component as a proxy.

The researchers found a gap anyway. There is a trusted component, a script interpreter, that would accept an untrusted script (or list of commands to run) and could be manipulated into delivering that script to the main ChatGPT process. Patrick Wardle, an Objective-See Foundation software analyst and longtime macOS researcher, explains the trick: the app also checks the parent and grandparent of the calling process, but the malicious script simply spawns the script interpreter three times and then makes the request, which satisfies the checks.

The flaw could only be exploited by an attacker who already had malware installed on the target machine. Wardle calls it "insanely trivial" to exploit; his proof of concept needed only about a dozen lines of code. Beyond reading chat logs, the bug could be used to make ChatGPT run commands for the attacker, such as accessing a browser or other sensitive applications, with the requests appearing as legitimate instructions issued by the OpenAI software.

Wardle will present analysis of a number of AI macOS application bugs at Objective by the Sea, an Apple-focused security conference, in November. He also recently found a now-patched flaw in the dictation feature of Meta's new Muse AI assistant, which a local attacker could have used to grab a mishandled authentication token and reach user data. He says he has already submitted a new finding to OpenAI about the integration between ChatGPT and the company's new always-on Dots AI assistant; OpenAI is reviewing the report.

Wardle's broader warning is that AI agents need wide access to do their job, "like the building manager who has access to the keys to all the rooms," so a corrupted agent is a serious problem. He adds that AI companies are fixated on adding features, that more features mean a broader attack surface, and that security still often seems like an afterthought. WIRED updated the story on October 2, 2026 to elaborate on how the flaw could be exploited.

Key facts

  • Objective-See Foundation researchers found a flaw in the macOS ChatGPT app that could have given an attacker access to all chat logs, other stored app data and interconnections like browser sessions.
  • A trusted script interpreter accepted untrusted scripts; spawning it three times satisfied the app's parent and grandparent signature checks. Wardle's proof of concept needed about a dozen lines of code.
  • Exploitation required malware already installed on the target machine. The flaw is patched, and OpenAI acknowledged it and the fix in its change log on September 25.
  • The bug could also make ChatGPT run commands for the attacker, such as accessing a browser or other sensitive applications, appearing as legitimate OpenAI instructions.
  • Wardle says he has submitted a new finding to OpenAI about the ChatGPT and Dots integration; OpenAI is reviewing it.

Why it matters

The story shows what an AI app is worth to an attacker. Agents are given broad access to a machine to do their work, and Wardle compares them to a building manager holding the keys to every room. Compromise the agent and unprivileged code can potentially reach everything the agent can. WIRED frames the bug as an example of the deep system access and trust that AI platforms are afforded, and the target that puts on their backs.

Who it affects

People who use the ChatGPT app on macOS, since the flaw sat in that version of the app and exposed chat logs, other stored app data and links such as browser sessions. It also bears on anyone relying on AI agents that hold wide system access. The same researcher has found a patched dictation flaw in Meta's Muse AI assistant, so the pattern is not limited to OpenAI.

How to use it

The fix has already been released and OpenAI noted it in its system change log on September 25. The source does not say which app version contains the fix. The practical reading is to keep the ChatGPT app up to date. Wardle's talk on AI macOS application bugs at Objective by the Sea in November is the next place to look for more detail.

How solid is it

The account comes from WIRED, quoting Objective-See Foundation's Patrick Wardle, who describes the mechanism and his own proof of concept. OpenAI confirmed the flaw and fix publicly in its change log and gave a statement through spokesperson Shane Bauer. WIRED updated the article on October 2 to elaborate on how the flaw could be exploited. The source gives no CVE identifier or severity score.

Risks and caveats

The flaw could only be exploited by an attacker who already had malware on the target machine, which limits the exposure. No evidence is given that it was exploited in the wild. OpenAI's statement does not describe the specific fix. Wardle says a further finding about the ChatGPT and Dots integration is under review, and the source gives no details beyond that.

“Agents need a lot of access to do their job. They are like the building manager who has access to the keys to all the rooms.”

— Patrick Wardle, Objective-See Foundation software analyst, to WIRED