Security & AI news

AI apps on macOS · By FireAI Security & Research Team · Published

Objective-See researchers find a flaw in the ChatGPT macOS app that exposed chat logs to local attackers

Objective-See researchers found that a trusted script interpreter let local code pass the ChatGPT Mac app’s signature checks; OpenAI noted the fix on 25 September 2026.

A chat bubble with a warning sign and the FireAI activity mascot, next to the words “ChatGPT Mac app flaw exposed chat logs.”

WIRED reported on 2 October 2026 that researchers at the Objective-See Foundation found a now-patched vulnerability in the macOS version of OpenAI's ChatGPT app. The flaw could have been used to take over the app on a victim's computer and reach the chat logs and other data it stores [1]. The finding is relevant to Mac users because it concerns the trust placed in AI applications that hold conversation histories and can act on the computer.

Background

The ChatGPT macOS app consists of several components that communicate with each other. According to WIRED, they confirm through digital signatures that a request comes from an OpenAI component and not from outside software, and the design requires these checks at three layers of separation from the request [1]. OpenAI acknowledged the flaw and its fix in its change log on 25 September 2026 [1].

Findings

The Objective-See researchers found a trusted component, a script interpreter, that accepts an untrusted script and can be made to deliver it into the main ChatGPT process. Patrick Wardle, a software analyst at the foundation, is quoted as saying that the checks also cover the parent and the grandparent of the requesting process, but that a malicious script can start the interpreter three times and then make the request, which satisfies the requirements [1].

WIRED states that the flaw could only be exploited by an attacker who already had hostile software running on the target machine. Wardle described it as "insanely trivial" to exploit, and his proof of concept needed about a dozen lines of code. Besides access to chat logs, the flaw could be used to make ChatGPT run commands for the attacker, such as reaching a browser or other sensitive applications, with the requests appearing as legitimate instructions from the OpenAI software [1]. The420.in repeats this account and adds the advice to keep ChatGPT and the operating system updated [2].

An OpenAI spokesperson, Shane Bauer, told WIRED: "We continue to evolve our security practices, but recognize a need to move faster." Wardle told WIRED that the more features AI companies add, the broader the attack surface becomes, and that security still often seems an afterthought. He said he has submitted a further finding to OpenAI about the integration between ChatGPT and the always-on Dots assistant, which OpenAI is reviewing, and plans to present analysis of several AI macOS application bugs at the Objective by the Sea conference in November [1].

Implications for Mac users

The flaw was a second-stage problem: it required hostile code to be present already, and it was fixed before the report appeared [1]. Its significance lies in what it shows about AI apps as targets. An app that stores conversation history and can drive a browser holds more of a person's information than most single applications, so a weakness in its internal trust checks has a wider reach.

Recommendations

  1. Keep the ChatGPT app, and any other AI assistant on the Mac, updated, and install macOS updates as they arrive.
  2. Install software only from sources that can be verified, since the reported flaw needed hostile code on the machine.
  3. Review which AI apps hold broad permissions in System Settings, under Privacy and Security, and remove those that are not needed.
  4. Treat stored chat histories as sensitive files and avoid placing credentials or personal documents in them.
  5. Check which AI apps connect to the internet and to which destinations.

Relevance to FireAI

FireAI is a firewall for one Mac. Its Agent profile recognises ChatGPT, including OpenAI's dots, among 19 AI agents, learns where each normally connects, and flags a first-ever destination or an upload spike, using only host names and byte counts. The Activity page lists every app that went online, newest first.

FireAI does not fix flaws in other vendors' apps, does not inspect the signature checks inside the ChatGPT app, and cannot prevent local code from abusing an app's internal components. It does not read chat logs or the content of connections. It can show where an app sends data over the network; it cannot show what a local process asked an app to do.

Limitations

The account rests on WIRED's reporting and one secondary summary. This item did not fetch OpenAI's change log, so the wording of the fix and the affected app versions are not stated here. The sources do not report any exploitation of the flaw outside the researchers' proof of concept, and WIRED notes that its article was updated on 2 October to elaborate on how the flaw could be exploited [1].

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. WIRED, 2 October 2026: A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
  2. The420.in, 3 October 2026: ChatGPT Mac App Flaw Could Have Exposed User Chats to Hackers