The macOS version of OpenAI’s ChatGPT client contained a security defect that researchers at the Objective-See Foundation say could let an adversary seize control of the application on a target computer. By exploiting the flaw, an attacker would gain visibility into all stored conversation histories and could tap into linked browser sessions. The issue was publicly disclosed by OpenAI on September 25.
The client is built from several processes that exchange messages only after confirming each other’s digital signatures. OpenAI designed the system to perform these checks at three separate stages, intending to guarantee that any request originates from an authorized component rather than from external or malicious software. This layered verification was meant to block proxy attacks.
Researchers identified a trusted component,a script interpreter,that would accept a command list without verifying its provenance. By launching the interpreter three times, a malicious script can satisfy the parent-and-grandparent checks and be injected into the main ChatGPT process. Wardle explained that the script spawns the interpreter repeatedly, allowing the request to meet the required validation chain.
The exploit was described as “insanely trivial” by the discoverer, who demonstrated a proof-of-concept consisting of roughly a dozen lines of code. Beyond reading conversation logs, the vulnerability could be leveraged to command the client to open a browser, launch other sensitive applications, or execute arbitrary system instructions appearing to come from OpenAI software.
OpenAI acknowledged the flaw in a system change log dated September 25 and issued a patch shortly thereafter. In a statement, spokesperson Shane Bauer said, “We continue to evolve our security practices, but recognize a need to move faster.” The company emphasized ongoing improvements while noting the urgency of addressing such vulnerabilities.
Wardle plans to discuss this and several other macOS AI application vulnerabilities at Objective by the Sea, an Apple-focused security conference scheduled for November. The session will review the technical details of the ChatGPT bug, the mitigation steps taken, and broader implications for AI-driven desktop software.
The researcher also disclosed a recently fixed issue in Meta’s Muse AI dictation feature that could let a local attacker capture a mishandled authentication token and access user data. Additionally, he submitted a new report concerning the integration between ChatGPT and OpenAI’s always-on Dots assistant, which OpenAI is currently reviewing.