Forklog Vulnerability in ChatGPT macOS App Exposes User Data
Article Content
- •Vulnerability CVE-2026-100754 allows unauthorized access to ChatGPT data.
- •Exploitation involved bypassing trust verification through a script interpreter.
- •OpenAI released a patch on September 25, 2026, to address the issue.
A vulnerability (CVE-2026-100754) in the ChatGPT macOS app allowed unprivileged code to impersonate trusted OpenAI components, potentially accessing user conversations and sensitive data. Discovered by Objective-See Foundation, the flaw was due to a script interpreter that could execute untrusted code, bypassing trust verification mechanisms. OpenAI acknowledged the issue and released a patch on September 25, 2026. The vulnerability was described as 'insanely trivial' to exploit, requiring only a few lines of code. While the flaw did not grant unrestricted access to all Mac content, it allowed access to data and resources already authorized for ChatGPT. OpenAI has committed to enhancing its security practices in light of this incident.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Meta and CVE-2026-100754 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is CVE-2026-100754?
How was the vulnerability exploited?
What should users do now?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…