How the app’s checks were bypassed
ChatGPT for macOS uses several components that verify one another’s digital signatures. The checks are designed to establish that a request comes from an OpenAI component, not from potentially malicious software, with three layers between the request and its source.
Objective-See Foundation researchers found that a trusted component—the app’s script interpreter—would accept a script or command list from an untrusted source. That gave an attacker a way to pass a script into ChatGPT’s main process. The app checked the parent process and the process above it, but researcher Patrick Wardle said a malicious script could launch the interpreter three times and then send a request that passed those checks.
Wardle, a software analyst at Objective-See Foundation and a longtime macOS researcher, said he needed roughly a dozen lines of code to demonstrate the attack. The flaw could expose ChatGPT conversations and let an attacker make the app run commands, such as accessing a browser or other sensitive apps. Those requests would appear to come from OpenAI software.
Wardle compared AI agents to building managers with keys to every room: broad access helps them do their jobs, but a breach or impersonation can put the data within reach of a less-privileged program.
OpenAI spokesperson Shane Bauer told WIRED that the company continues to improve its security methods, while acknowledging that it needs to move faster.
A wider target than one app
The Mac vulnerability sits alongside other AI-app security reports from Wardle:
I think the more important signal is the pattern, not the dozen lines of code. AI apps are gaining access to more tools and data, while their security is still treated as secondary by some companies, Wardle says. The announcement does not say whether the Dots report has anything in common with the patched ChatGPT flaw; what matters is that the integration is another place where trust has to be enforced.
OpenAI has fixed this vulnerability, but the underlying tension remains: the more an AI assistant can do on a user’s behalf, the more valuable it becomes to an attacker who can make it act as them.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X