ChatGPT Mac App Flaw Could Have Exposed User Chats to Hackers

The420.in Staff
5 Min Read

A security flaw in the macOS version of ChatGPT could have allowed attackers with malware already installed on a Mac to take control of the app, access stored chat logs and interact with connected services such as browser sessions. The vulnerability has since been fixed.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

What Could the ChatGPT Mac Flaw Allow?

Researchers found that the vulnerability could potentially be exploited to effectively take over ChatGPT on a victim’s computer.

An attacker could gain access to chat logs and other information stored by the application. The flaw could also expose connections between ChatGPT and other services, including browser sessions.

The problem highlighted the level of system access given to AI applications so they can perform their intended functions. If such software is compromised, that access can potentially be turned against the user.

How Did the Vulnerability Work?

The ChatGPT macOS application contains multiple components that communicate with each other. Digital-signature checks are intended to ensure that requests come from legitimate components rather than malicious software.

Researchers, however, found that a trusted component, described as a script interpreter, would accept an untrusted script and could then be manipulated into delivering it to the main ChatGPT process.

The security checks examined the parent and grandparent of that process but did not sufficiently scrutinise the malicious script itself, according to the findings.

This created a path through which malicious instructions could potentially be treated as trusted requests.

What Could an Attacker Do With the Flaw?

The vulnerability required an attacker to already have malware installed on the target Mac.

Once that condition was met, the flaw could potentially provide access to ChatGPT chat logs. Researchers said an attacker could also issue commands to ChatGPT or access a browser or other sensitive applications with requests appearing to come from legitimate software.

The researcher who examined the flaw described exploiting it as extremely easy once malware was already present on the device.

Has the Security Flaw Been Fixed?

The security flaw was acknowledged and a fix was included in a system change log on September 25.

A company spokesperson said security practices continue to evolve and acknowledged the need to move faster.

The disclosure means the vulnerability described by the researchers has been patched rather than remaining an unresolved flaw in the macOS application.

Why Does the Flaw Matter for AI Apps?

AI applications can require extensive access to computers and connected services to perform increasingly complex tasks. That access can become a security concern if the application itself is compromised.

One researcher compared AI agents with a building manager who has keys to every room. The concern is that compromising such a highly trusted application could potentially give malicious code access to resources that would otherwise remain protected.

The vulnerability therefore illustrates a broader security issue as AI applications become more deeply integrated with operating systems, browsers and other software.

Are Researchers Finding Similar AI Security Problems?

Researchers are continuing to examine security weaknesses in AI applications.

The researcher behind the ChatGPT findings had also identified a flaw in an AI assistant feature that could reportedly have been exploited by a local attacker to obtain data from a mishandled authentication token and gain access to user information.

A separate vulnerability involving integration between ChatGPT and another AI assistant was also submitted for review.

The findings underline the growing security challenge facing AI applications as developers add features that require deeper access to users’ computers and connected services.

What This Means for Users

The flaw could have exposed ChatGPT chat history and connected services on Macs already infected with malware. The vulnerability has been patched, making updated software important for users.

The420 Takeaway

AI apps can hold access to sensitive conversations and connected services, making vulnerabilities in the apps themselves a security risk. Users should keep ChatGPT and their operating system updated and avoid installing untrusted software.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected