OpenAI Patches ChatGPT macOS Flaw Exposing Chat Logs in 12 Lines of Code
Updated
Updated · WIRED · Oct 2
OpenAI Patches ChatGPT macOS Flaw Exposing Chat Logs in 12 Lines of Code
2 articles · Updated · WIRED · Oct 2
Summary
OpenAI fixed a critical ChatGPT macOS app vulnerability that could let attackers effectively take over the software on a victim’s machine and access stored chat logs, browser sessions and other linked data.
Objective-See researchers found the app’s signature checks could be bypassed by chaining a trusted script interpreter three times, allowing untrusted code to reach the main ChatGPT process; Patrick Wardle said the exploit needed only about a dozen lines of code.
The flaw also let attackers make ChatGPT run commands against browsers or other sensitive apps while those requests appeared to come from legitimate OpenAI software, highlighting how much system access AI assistants hold.
OpenAI disclosed the fix in its September 25 system change log and said it needs to move faster on security as AI companies keep expanding features that widen the attack surface.