Heise.De ChatGPT App for macOS Exposes User Data Due to Vulnerability
Article Content
- •A vulnerability in the ChatGPT app allows interception of sensitive user data.
- •OpenAI released a patch for the vulnerability identified as CVE-2026-100754.
- •Apple plans to tighten Full Disk Access controls in macOS to enhance user privacy.
A vulnerability identified in the ChatGPT app for macOS, with CVE ID 2026-100754, allows attackers to intercept sensitive information, including conversation history. Discovered by security researcher Patrick Wardle, this flaw is similar to one found in Meta's Muse app. OpenAI patched the vulnerability at the end of September 2026 after being informed by Wardle. The issue arises from the app's script interpreter, which can be exploited by executing malicious code. Apple plans to enhance controls for Full Disk Access in macOS to mitigate such risks, requiring explicit user consent for apps needing this permission. The exact scope of exploitation remains unclear, as users would need to execute the malicious code themselves. This incident highlights the risks associated with agentic tools that require extensive access rights.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is CVE-2026-100754?
How was the vulnerability discovered?
What actions should users take?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…