NEWS

Flaw in ChatGPT app for Mac allowed theft of users' sensitive data

Researchers at the Objective-See Foundation found a loophole

A recently patched vulnerability in the native ChatGPT app for macOS allowed an attacker to take control of the app on the victim's machine, with access to the entire conversation history and integrations such as browser sessions. The flaw was discovered by researchers at the Objective-See Foundation and reported by Wired. OpenAI acknowledged the issue and published the fix in its security changelog on September 25, 2026.

The case matters less for the CVE itself and more for the pattern it reveals: the deeper the system access an AI agent receives to function, the larger the attack surface when that agent is compromised. For those who design or integrate this type of tool in production, the ChatGPT flaw is a case study in how a trust architecture that looks solid on paper can fail in implementation.

How the flaw worked

The ChatGPT app for Mac is divided into multiple internal components that need to communicate with one another. To ensure that this communication only happens between legitimate OpenAI processes, and not with malicious software posing as them, the system checks digital signatures. The security design goes beyond the basics: the signature check is required at three layers of distance from the original request, to prevent a malicious process from using a trusted component as a proxy.

In practice, this defense in depth had a blind spot. One of the trusted components is a script interpreter, which accepts a list of commands and can forward it to the main ChatGPT process. The researchers found that this interpreter checked the parent process and the grandparent process of the call, but did not prevent a malicious script from simply spawning the interpreter itself three times in a row before making the request, satisfying the checks without ever having come from a real OpenAI component.

They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements.

Patrick Wardle, software analyst at the Objective-See Foundation

According to Wardle, the proof of concept that exploited the flaw needed just over a dozen lines of code, something he describes as "insanely trivial" to exploit. Once inside the main process, the attacker had access to the conversation logs stored by the app and could make ChatGPT execute commands on the attacker's behalf, such as accessing the browser or other sensitive applications, all while appearing to be a legitimate instruction issued by OpenAI's own software.

Why this is an architecture problem, not just a code problem

The central point raised by Wardle is not the specific bug, but the trust model behind it. AI agents need broad permissions to automate tasks, read files, trigger operating system actions, and integrate with other apps. This is, at the same time, the reason the product exists and the reason it becomes a priority target.

Agents need a lot of access to do their job. They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that's super problematic. It can mean that unprivileged code could then potentially have access to all the things.

Patrick Wardle, software analyst at the Objective-See Foundation

Contacted by Wired, OpenAI confirmed the issue and the fix through spokesperson Shane Bauer, who publicly acknowledged the gap between the evolution of the company's security practices and the speed needed to keep up with the risks.

We continue to evolve our security practices, but recognize a need to move faster.

Shane Bauer, OpenAI spokesperson

What changes for those developing with AI agents

This is not an isolated incident. Wardle also found, and already saw fixed, a flaw in the dictation feature of Meta's Muse assistant, which allowed a local attacker to capture a mishandled authentication token and access user data. And he has already submitted to OpenAI a new finding related to the integration between ChatGPT and Dots, the company's always-on assistant, still under review.

For teams that package ChatGPT, Claude, Copilot, or any agent with access to the file system, browser, or credentials inside a product, the episode suggests three concrete areas for review:

  • Don't rely solely on signature verification between processes: the chain of checks (process, parent, grandparent) looks robust, but any entry point that accepts unsigned commands, such as a script interpreter, can be used to forge the entire chain.
  • Treat the agent as an attack surface, not just as a feature: every new permission granted to an agent (reading history, controlling the browser, triggering commands) is a new vector that needs its own isolation, not just a shared authentication layer.
  • Audit third-party AI apps before releasing them into a corporate environment: if an established app like ChatGPT desktop had this kind of loophole, any AI integration with broad access to the team's operating system deserves the same level of scrutiny given to other critical dependencies.

Wardle will present the full analysis of bugs found in different AI apps for macOS at Objective by the Sea, an Apple-focused security conference, in November. He sums up the diagnosis that drives the Objective-See Foundation's work in this field.

AI companies are fixated on adding features right now. But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought.

Patrick Wardle, software analyst at the Objective-See Foundation

What remains open

The fix for the flaw in ChatGPT's macOS app has been in production since September 25, 2026, according to the OpenAI changelog cited by Wired. What remains unresolved is the next chapter: the new vulnerability involving the integration between ChatGPT and Dots, reported by Wardle, is still under review by OpenAI, with no disclosed fix timeline. For those who depend on these products in a production workflow, it's worth following OpenAI's security changelog and treating any agent with broad system access as a component that needs continuous monitoring, not permanent trust.

Translated from the Brazilian Portuguese original · Read the original