ChatGPT's Mac app had a flaw that let malware take it over, now patched

By EnkiEdited by VK, Editor

Published

Reporting from WIRED

A researcher found that malware already on a Mac could slip commands into OpenAI's ChatGPT app, read stored chats and drive connected apps. OpenAI logged the fix on September 25.

What it means for founders

  • Update the ChatGPT Mac app on every company machine and confirm the version, especially where staff have connected it to browsers, email or internal tools.
  • If you build a desktop agent, signature checks on calling processes are not enough on their own. Inventory every signed helper you ship, particularly interpreters and plugin hosts, because any component that executes arbitrary input can launder an attacker's request.
  • Budget for outside security review before you add connectors. Each integration widens what a compromised agent can reach, and researchers are now testing AI apps specifically.
  • Watch for Wardle's November talk and OpenAI's response on Dots. If that integration bug is serious, it will shape how much access teams are willing to give always-on agents.

The story

OpenAI has fixed a vulnerability in the macOS version of ChatGPT that could have let malicious software on a Mac take control of the app, read its stored conversations and issue commands that looked like they came from OpenAI's own code. The company noted the fix in its change log on September 25, and WIRED reported the details on Thursday. The flaw was found by Patrick Wardle and colleagues at the Objective-See Foundation, a nonprofit focused on Mac security.

How it worked

The ChatGPT app is built from several cooperating processes. Before one accepts a request from another, it checks the sender's code signature, and it checks that process's parent and grandparent too, so an outside program cannot simply route a request through a trusted OpenAI component. Wardle's team found a gap: one signed component is a script interpreter that will run whatever script it is handed. An attacker could launch that interpreter three levels deep, satisfying every signature check, and then feed it instructions of their own.

With that foothold, the attacker could pull chat logs and other data the app stores, and could tell ChatGPT to act on connected resources such as browser sessions, with the activity appearing legitimate. Wardle told WIRED his proof of concept took about a dozen lines of code. The important limit is that the attack required malware already running on the target Mac. It was a way to deepen an existing infection, not a way in.

OpenAI spokesperson Shane Bauer told WIRED the company keeps evolving its security practices but recognizes it needs to move faster.

A pattern, not a one-off

Wardle has been working through AI desktop apps. He previously reported a since fixed bug in the dictation feature of Meta's Muse that exposed an authentication token, and says he has sent OpenAI a new finding about how ChatGPT connects to Dots, its always-on agent, which OpenAI is reviewing. He plans to present more AI app bugs at the Objective by the Sea conference in November. His argument is simple: agents are trusted with the keys to everything, so whoever corrupts the agent gets the keys too.

The disclosure landed the same day Apple said it would make Full Disk Access, the broadest macOS permission, harder to grant because of the risks AI agents bring.

What we don't know yet

There is no public evidence the flaw was exploited before the fix. OpenAI has not said which app versions were affected, and the Dots finding has not been described in detail.

Sources

Enki Daily

Get stories like this every weekday morning.

The day's AI stories for founders, each with what it means for your company. Free.

Tools in this story

We may earn a commission if you sign up through our links. It never affects our ratings or which stories we cover.

ChatGPT

OpenAI's all-purpose AI assistant

9.2Editor’s scoreVisit ChatGPT

More in Policy & Safety

How Enki covers newsCorrectionsReport an error

Search Enki

Search AI tools, categories and news