ChatGPT's Mac App Had a Flaw That Could Expose Your Private Chats
Your AI assistant might have been a backdoor for hackers—here's what you need to know.
A recently fixed security flaw in OpenAI's ChatGPT app for Mac computers could have allowed hackers to take over the app and steal your private conversations. The bug was discovered by security researchers at the Objective-See Foundation. It was patched on September 25, according to OpenAI's change log. The flaw was serious because ChatGPT has deep access to your system to function—like a building manager with keys to every room. If corrupted, an attacker could read all your chat logs, access your browser sessions, and even make ChatGPT run commands on your computer.
The good news: this flaw could only be exploited if a hacker had already installed malware on your Mac. So it wasn't a remote attack from the internet. But the bad news: once malware was on your machine, exploiting the bug was "insanely trivial," according to researcher Patrick Wardle. It took only about a dozen lines of code. The attacker could then make ChatGPT perform actions that looked legitimate, like opening your browser or other sensitive apps.
This isn't an isolated incident. Wardle also found a similar flaw in Meta's new Muse AI assistant, which has been patched. And he's submitted another vulnerability report to OpenAI about its new Dots AI assistant. He warns that AI companies are racing to add features but often treat security as an afterthought. As AI apps become more common, they become bigger targets for hackers.
For everyday users, this means you should keep your apps updated, be cautious about downloading unknown software, and understand that AI assistants have a lot of access to your personal data. OpenAI says it's evolving its security practices, but experts say the industry needs to move faster. The incident highlights a trade-off: the more helpful an AI is, the more access it needs—and the more damage a security hole can cause.
- A bug in ChatGPT's Mac app could have let hackers read all your chats and control other apps, but it was fixed in September.
- The flaw was easy to exploit, but only if your computer was already infected with malware—so it wasn't a remote attack.
- This isn't the first AI security issue; similar flaws were found in Meta's AI assistant, and experts say AI companies need to prioritize security more.
Why It Matters
Your AI assistant has access to your private data—if hacked, it could expose everything.