The FireAI Security Blog

By FireAI Security & Research Team · Published

Monitor the ChatGPT Mac App Network Connections: Security on Mac

Monitor the ChatGPT Mac App Network Connections: Security on Mac

The ChatGPT app for macOS is OpenAI’s native client for ChatGPT. Unlike a browser tab, a desktop app is a program on your Mac with its own network connections, and it can be updated, extended and attacked like any other program. This article covers what is publicly reported about its security, what a network firewall can and cannot tell you about it, and how FireAI treats it.

A reported flaw in the Mac app

In 2026, WIRED reported on a flaw in ChatGPT’s Mac app that could have let hackers grab sensitive data, discovered by researchers at the Objective-See Foundation. WIRED describes the vulnerability as recently patched, and quotes the macOS researcher Patrick Wardle on how much system access and trust AI apps are given on a Mac. The report, titled “A flaw in ChatGPT’s Mac app could have let hackers grab sensitive data”, is the primary source, and the wording “could have” in its title is worth keeping: it describes a weakness that existed, not data that is known to have been taken. Read the article for the technical details. Keep the ChatGPT app updated so the fix is installed.

The lesson for readers is general and does not depend on the details. Software that handles your conversations and files can contain bugs, and keeping the app updated is the first defence. A firewall is a second, independent layer: it can show where the app sends data, whatever the cause.

How FireAI treats ChatGPT

FireAI’s Agent profile list includes ChatGPT, and notes that OpenAI’s dots reach the Mac through it. FireAI therefore watches the ChatGPT app as an agent, with its own character in the AI agents card. The app is recognised by the app it runs from.

What a network view shows about a chat app

A firewall sees host names and byte counts, not the conversation. For a chat app that is still informative in two ways. The first is the set of hosts the app normally uses: once FireAI has learned them, a first-ever destination stands out. The second is volume: an app that normally sends short prompts and suddenly sends a very large upload in one hour is worth investigating, whatever it was doing. FireAI’s upload spike rule is exactly that comparison, against the app’s own busiest hour.

Neither check tells you why. A large upload can be you attaching a large file or a legitimate sync. The point is that you decide with the facts in front of you, rather than never seeing the event.

Practical checks that need no extra tool

  • Keep the app updated, and prefer downloading it from OpenAI’s own site.
  • Be selective about what you attach to a chat, since an attachment leaves your Mac by design.
  • Review which other apps and extensions you have given access to, in System Settings under Privacy and Security.

Watching the ChatGPT Mac app with FireAI

FireAI is a firewall for macOS made by HisnLabs, and since version 1.0.2 it has a feature called Agent profile. It recognises 19 AI agents, learns where each one normally connects, and flags unusual behaviour for you to review. ChatGPT, including OpenAI’s dots, which reach the Mac through it, is recognised by the app it runs from.

the ChatGPT Mac app is matched by the app it runs from, which means FireAI labels the match and does not verify it against a developer signature. Only Claude Code, Claude and Cursor are checked that way.

FireAI also recognises the agent’s child processes, such as a shell, git or curl that the agent runs, by walking up the process’s parents until it reaches the agent. Those connections are therefore counted as the agent’s own.

What FireAI flags

  1. For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain. Nothing is flagged during this learning period.
  2. After that, a first-ever destination outside the learned baseline is flagged for review.
  3. An upload spike is flagged too: an hour in which the agent sent at least 4 times its busiest hour so far, and never less than 25 MB.

Agent profile uses only metadata, meaning host names and byte counts. FireAI never reads the payload of a connection, and it cannot read inside an encrypted one.

Set it up for the ChatGPT Mac app

  1. Install FireAI and finish the setup, then keep using the ChatGPT Mac app as you normally do. The 3-day learning period starts from what FireAI sees.
  2. Open Suggestions and look at the AI agents card. It lists the agents FireAI has recognised and what it has learned about each.
  3. When the ChatGPT Mac app reaches a destination it has never contacted, the flag appears in the AI agents card and in Quick Review. Swipe left to block, or right for “It’s fine”.
  4. Block creates a rule for the process that connected. “It’s fine” adds the destination to the agent’s baseline so it is not flagged again.
  5. If you want the agent kept to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Once the agent has finished learning, a connection to a destination outside its baseline is blocked instead of flagged.
  6. A blocked destination shows in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent can reach it right away. Keep blocked creates a block rule, so the destination stays blocked in every mode.

Limits

  • FireAI does not prevent prompt injection. A prompt hidden in a web page or a file can still steer an agent. What FireAI can do is flag, and let you block, the path data would take out of your Mac.
  • FireAI cannot see prompts, the contents of MCP tools, or which files the ChatGPT Mac app reads, such as ~/.ssh. TLS hides the payload, and FireAI is not inside the agent.
  • Child processes that exit very quickly may be missed, and child processes are matched by path, not by signature.
  • During the 3-day learning period nothing is flagged.
  • In the Agent profile mode, a connection to a bare IP address with no host name is matched by its address. If a service the agent normally uses answers from a new address, it is blocked until you allow it.
  • FireAI’s plain-words explanation of a flag is written from facts it measured. It never says a destination is safe or dangerous. The decision is yours.

Related guides

The same approach applies to the other agents FireAI recognises: Claude Code, the Claude desktop app, Cursor, Codex CLI, OpenClaw, Hermes Agent, Gemini CLI, GitHub Copilot CLI, Amp, Qwen Code, opencode, Aider, Goose, Crush, Windsurf, Kiro, Trae, Muse from Meta, any other AI agent run by Python or Node. The full feature description is in the Agent profile documentation.

How FireAI and HisnLabs fit in

A chat app is also a network client. FireAI shows where it connects and how much it sends.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.

Sources