A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

OpenAI fixed a security hole in its ChatGPT Mac app that could have let attackers steal chat logs, browser sessions and run…

By Vane October 2, 2026 2 min read
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

OpenAI fixed a security hole in its ChatGPT Mac app that could have let attackers steal chat logs, browser sessions and run commands on a user’s machine.

The flaw appeared in the macOS version of the application and was patched after researchers at the Objective-See Foundation identified it. The vulnerability would have let an attacker take control of the app, read all stored data and impersonate trusted OpenAI processes.

How the exploit worked

The app relies on digital signatures to verify that every component is genuine. These checks happen at three layers to stop malicious software from tricking a trusted part into acting as a proxy.

Researchers found a trusted script interpreter that could accept untrusted commands. An attacker could spawn this interpreter three times and then make a request. This satisfied the parent and grandparent checks, allowing the malicious script to run inside the main ChatGPT process.

Patrick Wardle, a software analyst and longtime macOS researcher, described the exploit as “insanely trivial”. A proof of concept required only about a dozen lines of code.

Once inside, an attacker could access chat history and force the app to open browsers or other sensitive programs. The requests would appear to come from legitimate OpenAI software.

What OpenAI said

OpenAI acknowledged the issue and the fix in its system change log on September 25. Shane Bauer, a spokesperson for the company, told WIRED: “We continue to evolve our security practices, but recognize a need to move faster.”

Broader risks for Mac apps

Wardle will present analysis of several bugs in AI macOS applications at Objective by the Sea, an Apple-focused security conference in November.

He recently found another flaw in the dictation feature of Meta’s new Muse AI assistant. That bug could have let a local attacker grab a mishandled authentication token and access user data. It has since been patched.

Wardle has also submitted a new report to OpenAI regarding the integration between ChatGPT and the company’s new always-on Dots AI assistant. OpenAI is currently reviewing that finding.

What it means

“AI companies are fixated on adding features right now,” Wardle says. “But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought.”

Scroll to Top