ChatGPT Mac App Vulnerability Bypassed Its Trust Checks
wired.com

ChatGPT Mac App Vulnerability Bypassed Its Trust Checks

Tech News
3 min read

Published by AINave Editorial

TL;DRA flaw in ChatGPT’s macOS app let an untrusted script reach the app’s main process despite layered checks intended to verify trusted components. OpenAI acknowledged a fix, and researchers said the vulnerability could have exposed stored chats and connected browser sessions.

A vulnerability in ChatGPT’s macOS app could have let untrusted code reach the app’s main process, putting chat logs and connected browser sessions at risk. OpenAI acknowledged the flaw and its fix in a system change log on September 25, according to WIRED. The report describes a potential exploit, not evidence that attackers used it.

How a trusted interpreter slipped past the checks

ChatGPT’s Mac app uses digital signatures to check that requests between its components come from OpenAI software. The checks also examine the requesting process’s parent and grandparent, intended to prevent outside code from borrowing a trusted component as a proxy.

Researchers at the Objective-See Foundation found a gap in that chain: a trusted script interpreter would accept an untrusted script and pass it into ChatGPT’s main process. Patrick Wardle, a software analyst at the foundation, said the exploit spawned the interpreter three times, satisfying the ancestry checks. His proof of concept took about a dozen lines of code, WIRED reported. The vulnerability and its mechanism show why checking a process’s apparent lineage can fail if a trusted component accepts instructions from untrusted code.

What access could have meant

Once code reached the main process, an attacker could potentially access ChatGPT chat logs and other data stored by the app, along with browser sessions and other connections. The flaw could also have let the attacker ask ChatGPT to run commands, including requests to access a browser or other sensitive applications. Those requests could appear to come from OpenAI software.

That distinction matters: the issue was not just whether local conversation data was protected. A compromised app could also act as a trusted intermediary to other software. The report does not establish that anyone exploited the flaw in real-world attacks.

Wardle compared AI agents with a building manager holding keys to many rooms: broad access helps them do their work, but makes compromise more consequential. Here, the practical risk came from the app’s own process trust boundary and the access available through its connections, not from a claim that every AI app shares this weakness.

OpenAI says it fixed the flaw

OpenAI’s spokesperson told WIRED that the company was evolving its security practices but recognized a need to move faster. The company publicly recorded the flaw and fix on September 25, though the supplied report does not give a fixed app version. Wardle separately said he had submitted a report about ChatGPT’s integration with the Dots AI assistant, which OpenAI was reviewing; that is distinct from this patched vulnerability. OpenAI’s acknowledgment and the separate review underline that security work continues as product integrations expand.

The central lesson is specific: signature checks can look thorough and still be undermined when a trusted component will carry untrusted instructions into a privileged process. As AI software connects to more local data and applications, the trust boundary around those connections becomes part of the product’s security surface.

FAQs

A trusted script interpreter accepted untrusted commands and could deliver them into ChatGPT’s main process, bypassing the app’s intended process checks. Researchers at Objective-See Foundation identified the flaw.

Sources

Latest Tech News