Skip to content
Vulnerability in ChatGPT macOS App Allowing Access to Conversations Fixed

Vulnerability in ChatGPT macOS App Allowing Access to Conversations Fixed

Forklog • October 2, 2026

A vulnerability was discovered in the ChatGPT app for macOS, allowing unprivileged code running on a computer to masquerade its commands as requests from trusted OpenAI components, potentially accessing conversations, data, and app integrations. Developers have fixed the issue and disclosed the details, according to WIRED .

The vulnerability was identified by researchers from the Objective-See Foundation. It has been assigned the identifier CVE-2026-100754, and the patch was included in app version 26.924.20706. OpenAI representative Shane Bauer told the publication that the developer continues to improve security practices but acknowledges the need to move faster.

Bypassing Trust Verification

The attacker exploited features of the app’s local architecture and the trust mechanism between processes.

ChatGPT app components verify each other’s digital signatures to distinguish trusted OpenAI processes from third-party software. This verification extended not only to the process directly sending the request but also to its parent and grandparent processes.

Researchers found a script interpreter in the trusted chain capable of executing untrusted code. According to them, a malicious script could sequentially activate the interpreter three times, after which the main app process would perceive the request as coming from a trusted OpenAI component.

The potential consequences depended on the data and applications ChatGPT already had access to. According to WIRED, after bypassing the verification, local code could read conversation logs available to the app, interact with connected resources, and make ChatGPT execute commands with its own permissions.

For example, this could affect the browser or other applications if the user had previously granted ChatGPT the relevant access. To the system, such requests would appear to originate from a legitimate OpenAI component.

However, the vulnerability did not provide automatic access to all Mac content. The attack capabilities were limited to local ChatGPT data and resources to which the app already had authorized access.

The Objective-See Foundation linked such risks to the growing capabilities of AI assistants. To perform tasks, they gain access to the browser, other applications, and user data. Compromising such software potentially opens the way to more system resources.

In September, researchers from Hacktron AI gained access to OpenAI’s internal repository by intercepting an employee’s account. They were aided in finding a working attack method by Anthropic’s Claude models.

In 2024, OpenAI fixed a vulnerability involving unencrypted conversations with ChatGPT on macOS.

Follow ForkLog on social media Telegram (main channel) X Found a mistake in the text? Select it and press CTRL+ENTER

Follow ForkLog on social media

Bitcoin Red Team Returns to Chinese AI Models After OpenAI Restrictions

OpenAI Services Experience Global Outage

Researcher Identifies Two Vulnerabilities in Unitree Robots

Ethereum Foundation Utilizes AI Agents to Identify Protocol Bugs

Researchers Develop Adaptive AI Worm

Claude Opus 4.5 Identifies 22 Vulnerabilities in Firefox Within Two Weeks

Vibe Coding via Claude Opus Leads to Moonwell DeFi Project Breach

Critical Vulnerabilities Found in Clawdbot AI Agent for Cryptocurrency Theft

New Jailbreak Breaches AI Security in 99% of Cases

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)