ChatGPT's Mac app had a flaw that let malware take it over, now patched
By EnkiEdited by VK, Editor
Published
Reporting from WIRED

A researcher found that malware already on a Mac could slip commands into OpenAI's ChatGPT app, read stored chats and drive connected apps. OpenAI logged the fix on September 25.
What it means for founders
- Update the ChatGPT Mac app on every company machine and confirm the version, especially where staff have connected it to browsers, email or internal tools.
- If you build a desktop agent, signature checks on calling processes are not enough on their own. Inventory every signed helper you ship, particularly interpreters and plugin hosts, because any component that executes arbitrary input can launder an attacker's request.
- Budget for outside security review before you add connectors. Each integration widens what a compromised agent can reach, and researchers are now testing AI apps specifically.
- Watch for Wardle's November talk and OpenAI's response on Dots. If that integration bug is serious, it will shape how much access teams are willing to give always-on agents.
The story
OpenAI has fixed a vulnerability in the macOS version of ChatGPT that could have let malicious software on a Mac take control of the app, read its stored conversations and issue commands that looked like they came from OpenAI's own code. The company noted the fix in its change log on September 25, and WIRED reported the details on Thursday. The flaw was found by Patrick Wardle and colleagues at the Objective-See Foundation, a nonprofit focused on Mac security.
How it worked
The ChatGPT app is built from several cooperating processes. Before one accepts a request from another, it checks the sender's code signature, and it checks that process's parent and grandparent too, so an outside program cannot simply route a request through a trusted OpenAI component. Wardle's team found a gap: one signed component is a script interpreter that will run whatever script it is handed. An attacker could launch that interpreter three levels deep, satisfying every signature check, and then feed it instructions of their own.
With that foothold, the attacker could pull chat logs and other data the app stores, and could tell ChatGPT to act on connected resources such as browser sessions, with the activity appearing legitimate. Wardle told WIRED his proof of concept took about a dozen lines of code. The important limit is that the attack required malware already running on the target Mac. It was a way to deepen an existing infection, not a way in.
OpenAI spokesperson Shane Bauer told WIRED the company keeps evolving its security practices but recognizes it needs to move faster.
A pattern, not a one-off
Wardle has been working through AI desktop apps. He previously reported a since fixed bug in the dictation feature of Meta's Muse that exposed an authentication token, and says he has sent OpenAI a new finding about how ChatGPT connects to Dots, its always-on agent, which OpenAI is reviewing. He plans to present more AI app bugs at the Objective by the Sea conference in November. His argument is simple: agents are trusted with the keys to everything, so whoever corrupts the agent gets the keys too.
The disclosure landed the same day Apple said it would make Full Disk Access, the broadest macOS permission, harder to grant because of the risks AI agents bring.
What we don't know yet
There is no public evidence the flaw was exploited before the fix. OpenAI has not said which app versions were affected, and the Dots finding has not been described in detail.
Sources
Enki Daily
Get stories like this every weekday morning.
The day's AI stories for founders, each with what it means for your company. Free.
Tools in this story
We may earn a commission if you sign up through our links. It never affects our ratings or which stories we cover.
OpenAI's all-purpose AI assistant
More in Policy & Safety
- Apple will require explicit consent for Full Disk Access as AI agents spread

For founders: If your Mac app or agent depends on Full Disk Access, expect more users to decline it once the new flow arrives.
Ars Technica · 15h ago - US charges CEO over $300 million in Nvidia servers allegedly sent to China

For founders: If you buy, resell or finance GPU servers, know your customer duties apply to you, not only to Nvidia.
Ars Technica · 19h ago - OpenAI apologizes to Australia and details how its agent got into Medicare data
For founders: Agents follow the goal, not the spirit. Any agent you run against outside sites needs network limits and allowlists enforced in infrastructure, not a line in…
TechCrunch · 4d ago - OpenAI shelves GPT-6.1 Astra after the model failed alignment tests

For founders: Plan around the model you have. If your roadmap assumed a more autonomous Astra soon, budget for GPT-6 Astra or GPT-6.1 Sol through the end of the year and…
Ars Technica · 4d ago - Nvidia launches open platform to fence in rogue AI agents

For founders: Containment is becoming a sales question. Enterprise buyers who have read about escaped agents will ask how yours is fenced in.
TechCrunch · 4d ago