Skip to content
ChatGPT App for macOS Exposes User Data Due to Vulnerability

ChatGPT App for macOS Exposes User Data Due to Vulnerability

First seen 5 Oct 2026, 11:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 12:27 UTC
  • •A vulnerability in the ChatGPT app allows interception of sensitive user data.
  • •OpenAI released a patch for the vulnerability identified as CVE-2026-100754.
  • •Apple plans to tighten Full Disk Access controls in macOS to enhance user privacy.

A vulnerability identified in the ChatGPT app for macOS, with CVE ID 2026-100754, allows attackers to intercept sensitive information, including conversation history. Discovered by security researcher Patrick Wardle, this flaw is similar to one found in Meta's Muse app. OpenAI patched the vulnerability at the end of September 2026 after being informed by Wardle. The issue arises from the app's script interpreter, which can be exploited by executing malicious code. Apple plans to enhance controls for Full Disk Access in macOS to mitigate such risks, requiring explicit user consent for apps needing this permission. The exact scope of exploitation remains unclear, as users would need to execute the malicious code themselves. This incident highlights the risks associated with agentic tools that require extensive access rights.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
OpenAI patches ChatGPT vulnerability
OpenAI resolved the vulnerability CVE-2026-100754 after being informed by researcher Patrick Wardle.
Heise.De
2026-10-05
Apple announces tighter Full Disk Access controls
Apple plans to introduce new controls for Full Disk Access in macOS to protect user privacy as AI agents become more capable.
Helpnetsecurity

More articles in this cluster (2)

Following this threat?

Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2026-100754?
CVE-2026-100754 is a vulnerability in the ChatGPT app for macOS that allows interception of sensitive data.
How was the vulnerability discovered?
The vulnerability was discovered by security researcher Patrick Wardle, who reported it to OpenAI.
What actions should users take?
Users should ensure they have updated their ChatGPT app to the latest version to mitigate the vulnerability.