By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release

In pictures: the Best Places To Work Awards 2026

News Room News Room 2 October 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
News

A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

News Room
Last updated: 2 October 2026 15:15
By News Room 3 Min Read
Share
SHARE

Hardly a day goes by lately without news of AI agents autonomously hacking websites or AI tools being used by cybercriminals and scammers. But a recently patched vulnerability in the macOS version of OpenAI’s ChatGPT underscores the potential value to attackers of compromising AI software itself as these apps proliferate more and more.

The bug could have been exploited to essentially take over ChatGPT on a victim’s computer, giving an attacker access to all the chat logs and other data stored by the app, as well as interconnections like browser sessions. Discovered by researchers at the Objective-See Foundation, the vulnerability illustrates the deep system access and trust that AI platforms are afforded in order to work—and the target that this puts on their backs.

“Agents need a lot of access to do their job,” says Objective-See Foundation software analyst and longtime macOS researcher Patrick Wardle. “They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that’s super problematic. It can mean that unprivileged code could then potentially have access to all the things.”

OpenAI publicly acknowledged the security flaw and fix in its system change log on September 25. “We continue to evolve our security practices, but recognize a need to move faster,” OpenAI spokesperson Shane Bauer told WIRED in a statement.

The ChatGPT macOS app includes multiple components that communicate with each other securely by checking for digital signatures. The idea is to confirm with these validity checks that both processes are OpenAI components and not outside, potentially malicious software making a request. And the system design goes so far as to require these signature checks at three layers of remove from the request, to ensure that malicious software isn’t somehow directing an OpenAI component to be a proxy and make a seemingly trusted request.

Objective-See Foundation researchers found, though, that there is a trusted component, a script interpreter, that would accept an untrusted script (or list of commands to run) and could then be manipulated to deliver this script into the main ChatGPT process. “They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements,” Wardle says.

The vulnerability was “insanely trivial” to exploit, he adds, and his proof of concept only required about a dozen lines of code. In addition to accessing ChatGPT chat logs, the vulnerability could also be used to get ChatGPT to run commands for the attacker, such as accessing a browser or other sensitive applications, with the requests appearing as legitimate instructions issued by the OpenAI software.

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Keurig’s new machine uses plastic-free compressed coffee pucks

News Room News Room 2 October 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

Home Assistant says ‘Big tech ruined the cloud, so we’re out’

The open-source smart home platform Home Assistant is kicking the cloud to the curb —…

2 October 2026

Deliverance Dev Wants GTA 6 to Make Games More Expensive

Warhorse co-founder Martin Klima wants GTA 6 to “blaze a trail” for higher game prices.…

2 October 2026

Best Smart Cat Trackers of 2026: Fi Mini vs. Tractive

However, note that all tested models rely on GPS for location tracking. This means that…

2 October 2026
News

Trump’s Crazy AI Rebrand Was a Loyalty Test for Tech Execs—and It Worked

Seventy years ago last summer, a group of scientists met at Dartmouth College to discuss a wild idea—that machines might one day be capable of human-like thought processes. One of…

News Room 2 October 2026

Your may also like!

News

If a data center is camouflaged in the woods, will anyone hate it?

News Room 2 October 2026
Gaming

Reigns developer Nerial closes following “significant trading losses” over past two years

News Room 2 October 2026
News

Amazon Says It’s No Longer Using NDAs for Data Centers

News Room 2 October 2026
News

Amazon writes scary blog warning communities not to block data centers

News Room 2 October 2026

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?