REGULATION

A ChatGPT Mac App Flaw Could Have Handed Attackers Chat Logs and Browser Sessions

P Priya Sharma Oct 2, 2026 2 min read
Engine Score 8/10 — Important

tier-1 regulation

Editorial illustration for: A ChatGPT Mac App Flaw Could Have Handed Attackers Chat Logs and Browser Sessions
  • A patched flaw in ChatGPT’s macOS app could have let attackers take over the app.
  • Exposure included chat logs, stored data, and interconnections like browser sessions.
  • Objective-See researchers bypassed three layers of digital-signature checks via the app’s script interpreter.
  • OpenAI acknowledged the fix on September 25 and says it must “move faster” on security.

What Happened

A recently patched vulnerability in the macOS version of ChatGPT could have been exploited to effectively take over the app on a victim’s computer — exposing chat logs, stored data, and interconnections like browser sessions, Wired reported on October 2, 2026. The Objective-See Foundation discovered the flaw; OpenAI acknowledged the fix in its September 25 change log.

Why It Matters

The industry’s security story has focused on what AI agents do to other systems — breakouts and AI-assisted intrusions. This flaw flips the lens: the AI apps themselves are becoming the high-value target. As Objective-See’s Patrick Wardle puts it, agents are like a building manager holding “the keys to all the rooms” — subvert the app and unprivileged code inherits everything the assistant can touch.

Technical Details

The ChatGPT macOS app verifies that its components talk only to each other by checking digital signatures — three layers deep, so malware can’t use an OpenAI component as a proxy. Objective-See found a trusted component, a script interpreter, that would accept an untrusted script and could be manipulated to deliver it into the main ChatGPT process; spawning the interpreter three levels deep defeated the parent-and-grandparent checks. OpenAI spokesperson Shane Bauer told Wired the company recognizes “a need to move faster” on security.

Who’s Affected

Mac ChatGPT users should update to the patched version — the attack surface covered everything the app stores and connects to. Every vendor shipping desktop AI assistants inherits the same lesson about deep system access. Enterprises get a concrete case for treating AI apps as privileged software in threat models.

What’s Next

Expect more researcher attention on desktop AI apps — and scrutiny of how fast OpenAI’s security practices actually move, with its agents and apps now both under the microscope.

Share

Enjoyed this story?

Get articles like this delivered daily. The Engine Room — free AI intelligence newsletter.

Free · No spam · Unsubscribe anytime