A critical vulnerability in chatgpt's macOS app could have enabled data theft
A recently patched vulnerability in the macOS version of OpenAI’s ChatGPT app could have allowed attackers to access sensitive data, including chat logs and browser sessions. The flaw, discovered by researchers at the Objective-See Foundation, highlights the extensive system access granted to AI platforms. Patrick Wardle, a software analyst at Objective-See, explained that AI apps are like building managers with access to all rooms, making them prime targets if compromised. OpenAI acknowledged the issue and released a fix on September 25, emphasizing its commitment to improving security.
The vulnerability exploited a trusted script interpreter within the app, enabling malicious code to bypass security checks and execute commands as if they were legitimate. Wardle noted that the exploit required only a dozen lines of code, making it exceptionally easy to weaponize. He also highlighted ongoing security concerns, including a recently patched flaw in Meta’s Muse AI and a new vulnerability he reported to OpenAI related to its integration with the Dots AI assistant. Wardle stressed that AI companies must prioritize security over rapid feature development to reduce attack surfaces.