Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Opus 5.5 loves to tell you ‘this matters’ (and other AI writing tells)

    Sora Is Gone: A Step-by-Step Plan to Rescue Your AI Video Project

    How to Use Andi Search: A Practical Walkthrough With Real Queries

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»Free AI Tools»A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
    Free AI Tools

    A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

    By No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hardly a day goes by lately without news of AI agents autonomously hacking websites or AI tools being used by cybercriminals and scammers. But a recently patched vulnerability in the macOS version of OpenAI’s ChatGPT underscores the potential value to attackers of compromising AI software itself as these apps proliferate more and more.

    The bug could have been exploited to essentially take over ChatGPT on a victim’s computer, giving an attacker access to all the chat logs and other data stored by the app, as well as interconnections like browser sessions. Discovered by researchers at the Objective-See Foundation, the vulnerability illustrates the deep system access and trust that AI platforms are afforded in order to work—and the target that this puts on their backs.

    “Agents need a lot of access to do their job,” says Objective-See Foundation software analyst and longtime macOS researcher Patrick Wardle. “They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that’s super problematic. It can mean that unprivileged code could then potentially have access to all the things.”

    OpenAI publicly acknowledged the security flaw and fix in its system change log on September 25. “We continue to evolve our security practices, but recognize a need to move faster,” OpenAI spokesperson Shane Bauer told WIRED in a statement.

    The ChatGPT macOS app includes multiple components that communicate with each other securely by checking for digital signatures. The idea is to confirm with these validity checks that both processes are OpenAI components and not outside, potentially malicious software making a request. And the system design goes so far as to require these signature checks at three layers of remove from the request, to ensure that malicious software isn’t somehow directing an OpenAI component to be a proxy and make a seemingly trusted request.

    Objective-See Foundation researchers found, though, that there is a trusted component, a script interpreter, that would accept an untrusted script (or list of commands to run) and could then be manipulated to deliver this script into the main ChatGPT process. “They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements,” Wardle says.

    The vulnerability was “insanely trivial” to exploit, he adds, and his proof of concept only required about a dozen lines of code. In addition to accessing ChatGPT chat logs, the vulnerability could also be used to get ChatGPT to run commands for the attacker, such as accessing a browser or other sensitive applications, with the requests appearing as legitimate instructions issued by the OpenAI software.

    App ChatGPTs Data flaw grab hackers Mac sensitive
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleTavus’ AI looks, listens, and talks back live
    Next Article World’s first enhanced geothermal power plant completed in just 23 months
    • Website

    Related Posts

    Free AI Tools

    How to Use Andi Search: A Practical Walkthrough With Real Queries

    Free AI Tools

    Health Care Workers Are Tired of Cleaning Up Palantir’s Mess

    Free AI Tools

    Tavus’ AI looks, listens, and talks back live

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Opus 5.5 loves to tell you ‘this matters’ (and other AI writing tells)

    0 Views

    Sora Is Gone: A Step-by-Step Plan to Rescue Your AI Video Project

    0 Views

    How to Use Andi Search: A Practical Walkthrough With Real Queries

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Opus 5.5 loves to tell you ‘this matters’ (and other AI writing tells)

    0 Views

    Sora Is Gone: A Step-by-Step Plan to Rescue Your AI Video Project

    0 Views

    How to Use Andi Search: A Practical Walkthrough With Real Queries

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.