Critical macOS ChatGPT Flaw Exposed User Data and System Access
A recently patched vulnerability in the macOS version of **OpenAI**'s **ChatGPT** app could have allowed attackers to gain full control over the application, accessing chat logs, browser sessions, and potentially executing arbitrary commands. Discovered by researchers at **Objective-See Foundation**, the flaw highlights the significant security risks inherent in increasingly powerful AI agents with deep system access.
While AI agents are making headlines for autonomously hacking systems or aiding cybercriminals, a critical vulnerability in the **ChatGPT** macOS application underscores a different, yet equally concerning, attack vector: compromising the AI software itself.
Discovered by **Objective-See Foundation** software analyst **Patrick Wardle**, the flaw, now patched, could have granted an attacker complete control over the **ChatGPT** app on a victim's machine. This level of access would expose all chat logs and other sensitive data stored by the application, including interconnected browser sessions.
"Agents need a lot of access to do their job," explains Wardle. "They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, thatβs super problematic. It can mean that unprivileged code could then potentially have access to all the things."
**OpenAI** publicly acknowledged and fixed the security flaw, noting it in their system changelog on September 25. An **OpenAI** spokesperson, **Shane Bauer**, commented, "We continue to evolve our security practices, but recognize a need to move faster."
The **ChatGPT** macOS app employs multiple components that communicate securely through digital signature checks. These checks are designed to verify that both communicating processes are legitimate **OpenAI** components, preventing malicious software from making trusted requests. The system even incorporates three layers of signature checks to prevent malicious software from using an **OpenAI** component as a proxy.
However, **Objective-See Foundation** researchers found a critical bypass. A trusted script interpreter component would accept an untrusted script, or list of commands, which could then be manipulated to deliver this script directly into the main **ChatGPT** process. Wardle elaborated, "They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements."
Exploitation of this vulnerability required an attacker to already have malware installed on the target machine. Wardle described the exploit as "insanely trivial," requiring only about a dozen lines of code for his proof of concept. Beyond accessing **ChatGPT** chat logs, the vulnerability could also be leveraged to make **ChatGPT** execute arbitrary commands, such as accessing browsers or other sensitive applications, all while appearing as legitimate instructions from the **OpenAI** software.
Wardle is set to present further analysis of various AI macOS application bugs at the upcoming **Objective by the Sea** conference in November. His recent work includes a patched flaw in **Meta**'s **Muse** AI assistant's dictation feature, which could have exposed user data, and a new vulnerability report submitted to **OpenAI** concerning the integration between **ChatGPT** and the company's new **Dots** AI assistant, which is currently under review.
"AI companies are fixated on adding features right now," Wardle observes. "But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought."