October 4, 2026

Security researchers uncovered a vulnerability in OpenAI’s ChatGPT application for macOS that could have handed over complete control of the desktop client to any malicious code already running on a user’s machine. The bug, now fixed, allowed attackers to bypass trust checks between app components and inject commands that the main process would treat as legitimate.

Patrick Wardle, a prominent macOS security expert and founder of the Objective-See Foundation, spotted the issue. His proof-of-concept exploit consisted of roughly a dozen lines of code. “Insanely trivial,” he called it.

The vulnerability surfaced at a moment when AI assistants on the desktop are gaining deeper system permissions. Users grant these tools access to files, browsers, and workflows to boost productivity. That access turns them into high-value targets. Compromise one, and the attacker inherits its privileges.

OpenAI acknowledged the problem in a system changelog dated September 25. The company pushed a patch in version 26.924.20706. Spokesman Shane Bauer told WIRED that the team continues to refine security practices and recognizes the need to move faster.

ChatGPT’s Mac app relies on multiple signed components that verify one another’s legitimacy through digital signatures and process hierarchies. This defense-in-depth approach aims to prevent untrusted code from reaching the core application. But one trusted piece broke the chain: a script interpreter designed to accept and forward lists of commands.

Researchers discovered the interpreter checked only the immediate parent and grandparent processes. A clever attacker could spawn the interpreter three times in succession. Each launch satisfied the trust criteria without originating from an authentic OpenAI component. The final request landed in the main ChatGPT process with full privileges.

Once inside, the consequences scaled with the permissions the user had already granted. Attackers could read every stored conversation. They could issue commands that opened browsers, pulled data from connected accounts, or interacted with other sensitive applications. All of it would appear to the system as instructions coming directly from OpenAI’s own software. No alarms. No obvious red flags.

“They are like the building manager who has access to the keys to all the rooms,” Wardle explained in the WIRED report. “So if they can be corrupted or subverted, that’s super problematic. It can mean that unprivileged code could then potentially have access to all the things.”

This incident follows a pattern of security missteps for OpenAI’s desktop software. In 2024, developer Pedro José Pereira Vieito revealed that the newly launched ChatGPT Mac app stored user conversations in plain text within an unprotected directory at ~/Library/Application Support/com.openai.chat/. Any other process on the machine could read them without permission or prompts. The Verge covered the discovery, prompting OpenAI to release an update that encrypted the local data.

Even after that fix, the app was not fully sandboxed in the way Apple recommends for applications handling private information. Sandboxing would have restricted its ability to reach other parts of the system without explicit user consent. Instead, many users enabled Full Disk Access to let ChatGPT automate tasks across apps and files.

Apple took notice. On the same day the latest flaw made headlines, the company announced tighter controls over Full Disk Access on macOS. The feature, originally intended for backups, now carries heightened risks because AI agents often request it to perform complex operations. “Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” Apple warned developers in a new guidance post reported by TechCrunch.

The timing feels pointed. Recent incidents involving AI desktop tools have raised alarms. A journalist claimed Meta’s Muse agent read private messages without permission, though Meta disputed the account. Security experts demonstrated how local malware could hijack similar agents to take screenshots, write files, or exfiltrate data while masquerading as the legitimate assistant.

OpenAI’s own track record includes supply-chain incidents. Earlier in 2026, a compromise of the Axios JavaScript library led to malicious code in a GitHub workflow used for signing macOS apps. The company revoked and rotated certificates out of caution, forcing users to update their ChatGPT, Codex, and other desktop tools. No user data was accessed, OpenAI stated at the time, according to Forbes.

Yet the pattern persists. Each update adds capabilities. Computer History, rolled out in August 2026, records user actions on the Mac, summarizes them with AI, and stores plain-text Markdown files locally. Those summaries sit in a directory readable by any process running under the same account, as detailed in a September report from Cybersecurity News. The window for exposure lasts up to 48 hours before raw events are deleted.

Industry observers see a fundamental tension. AI agents need broad access to deliver on their promise. They browse the web, edit documents, control applications. That same reach makes them dangerous when subverted. Traditional malware must evade defenses and escalate privileges. A compromised AI assistant already possesses them and operates with the user’s trust.

Wardle’s work on the ChatGPT flaw and similar issues with Meta’s Muse highlights this shift. In one demonstration, he redirected Muse’s transcription to his own server and gained account access. The agent could then be instructed to perform actions on the attacker’s behalf without user alerts in many cases.

OpenAI has not disclosed evidence of active exploitation of the script-interpreter bug before the patch. The company says it continues to improve. But security researchers argue that these flaws reveal deeper architectural choices made in haste to ship consumer products.

Users face practical trade-offs. Granting Full Disk Access unlocks powerful automation yet expands the blast radius of any local compromise. Keeping the app sandboxed limits functionality. Many choose convenience. The latest vulnerability shows how quickly that decision can backfire.

Apple’s move to restrict Full Disk Access signals a broader industry reckoning. Platform makers, AI developers, and security teams must coordinate more closely as agents proliferate. Permissions models designed for traditional apps don’t fully address tools that act with delegated human intent.

For now, the patched ChatGPT app closes one door. The conversation about how much power to give these assistants, and how securely to contain them, continues. So does the race between researchers who find the gaps and the teams rushing to close them.

ChatGPT Mac App Flaw Exposed Chat Logs and Browser Sessions to Local Attacks first appeared on Web and IT News.

Leave a Reply

Your email address will not be published. Required fields are marked *