Skip to main content
Back to News
OpenAI patches ChatGPT Mac flaw that could expose chats and connected applications
Technology
2 min read
US

OpenAI patches ChatGPT Mac flaw that could expose chats and connected applications

The AMW Read

A concrete trust-boundary bypass meaningfully updates OpenAI's application-security baseline and illustrates the deployment risks of assistants with access to connected tools.
NoveltySignificance
Foundation Models · Player MapSafety / Alignment
OpenAI
OpenAI

Foundation Models / LLMs

View Company Profile

OpenAI patches ChatGPT Mac flaw that could expose chats and connected applications

OpenAI acknowledged a security flaw and fix for its ChatGPT macOS app in its September 25 change log, according to WIRED. Objective-See Foundation researchers found that a trusted script interpreter could accept an untrusted script and pass it into the main ChatGPT process. Repeatedly spawning the interpreter bypassed checks intended to verify the requesting process and its parent processes. Exploitation could give an attacker access to stored chat logs and let them issue commands through ChatGPT to reach browsers or other sensitive applications. The report describes potential exposure, not a confirmed theft of user data.

For foundation-model companies expanding into agent software, this finding makes application security part of the competitive equation. The relevant industry force is deployment safety: access that makes an assistant useful also increases the consequences of compromised software. Here, checks on signed components failed to establish whether the commands they carried were trustworthy. Wardle also reported a separate vulnerability involving ChatGPT's integration with OpenAI's always-on Dots assistant; OpenAI is reviewing that report. That finding remains distinct from the patched Mac flaw.

Builders should test whether trusted helper processes can relay untrusted commands across application boundaries, including through chains of parent processes. The concrete lesson is to validate the origin and authority of a request rather than rely solely on the identity of the software delivering it. For investors assessing agent products, security review should examine connected-app permissions and patch responsiveness alongside feature breadth: a compromise of the assistant can potentially extend into the tools users authorize it to access.

#OpenAI #ChatGPT #AIAgents #ApplicationSecurity #macOS

#OpenAI#ChatGPT macOS#AI agent security#Objective-See Foundation

How This Connects

Based on Foundation Models · Player Map

  1. 1h agoOpenAI patches ChatGPT Mac flaw that could expose chats and connected applications · THIS ARTICLE
  2. 7h agoAnthropic reportedly secures up to $42B in Broadcom financing for AI infrastructureAnthropic
  3. 5d agoDeepSeek Reports $1B Run Rate as It Pursues $7.45B Round and Shanghai IPODeepSeek
  4. 1w agoGemini broke containment during a safety test and breached three real companies before Google disclosed itGoogle (Gemini)
  5. 0mo agoAbliteration.ai turns guardrail removal into a hosted commercial service for open-weight models.Abliteration
  6. 1mo agoZhipu AI (智谱) released GLM-5.3, a new open-weight foundation model with advanced cybersecurity capab...Z.ai

Related News

More news from OpenAI

Stay updated with the latest news and announcements from OpenAI.

View all OpenAI news

Discover AI Startups

Explore 5,000+ AI companies with VC-grade analysis, funding data, and investment insights.

Explore Dashboard