Policy

OpenAI Patches Security Flaw in ChatGPT Mac App

OpenAI has resolved a critical vulnerability in its ChatGPT macOS application that could have allowed local malware to hijack the assistant and steal sensitive user conversations.

WIRED AI4 days agoPolicy
Image: WIRED AI

OpenAI recently patched a security vulnerability in its ChatGPT application for macOS that could have allowed malicious actors to compromise the software and steal sensitive user data. Discovered by researchers at the Objective-See Foundation, the flaw permitted attackers to bypass the application's internal security checks. OpenAI acknowledged the issue and released a fix in its system change log on September 25.

The vulnerability targeted the app's internal communication system, which uses digital signatures to verify that requests originate from trusted OpenAI components. To prevent malicious software from acting as a proxy, the app required signature checks at three layers of process removal. However, security analyst Patrick Wardle discovered that a trusted script interpreter within the app could be manipulated. By spawning the interpreter three times, a malicious script could satisfy the three-layer validation requirement. Wardle noted that the exploit was "insanely trivial" to execute, requiring only about a dozen lines of code, though it did require the attacker to already have malware installed on the victim's machine.

If exploited, the bug allowed unauthorized code to access ChatGPT chat logs, browser sessions, and other connected data. It could also force ChatGPT to execute commands, such as opening a browser or accessing other sensitive applications, under the guise of legitimate user instructions. Wardle, who plans to present his findings at the Objective by the Sea security conference in November, has also identified vulnerabilities in other AI tools. These include a recently patched flaw in the dictation feature of Meta's Muse AI assistant that leaked authentication tokens, and a newly reported bug in the integration between ChatGPT and OpenAI's always-on Dots AI assistant.

For AI developers and security practitioners, this flaw highlights the significant risks associated with the deep system access granted to autonomous agents. As companies rush to integrate always-on assistants and cross-app functionalities, they expand their software's attack surface. Practitioners must prioritize rigorous local process validation and treat security as a foundational requirement rather than an afterthought during rapid feature deployment.

This is our own summary of reporting by WIRED AI

More in Policy