Skip to content
Vulnerability in ChatGPT macOS App Exposes User Data

Vulnerability in ChatGPT macOS App Exposes User Data

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 08:03 UTC
  • •Vulnerability CVE-2026-100754 allows unauthorized access to ChatGPT data.
  • •Exploitation involved bypassing trust verification through a script interpreter.
  • •OpenAI released a patch on September 25, 2026, to address the issue.

A vulnerability (CVE-2026-100754) in the ChatGPT macOS app allowed unprivileged code to impersonate trusted OpenAI components, potentially accessing user conversations and sensitive data. Discovered by Objective-See Foundation, the flaw was due to a script interpreter that could execute untrusted code, bypassing trust verification mechanisms. OpenAI acknowledged the issue and released a patch on September 25, 2026. The vulnerability was described as 'insanely trivial' to exploit, requiring only a few lines of code. While the flaw did not grant unrestricted access to all Mac content, it allowed access to data and resources already authorized for ChatGPT. OpenAI has committed to enhancing its security practices in light of this incident.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-25
Patch released for CVE-2026-100754
OpenAI released a fix for the vulnerability in the ChatGPT macOS app, addressing the exploit that allowed unauthorized access to user data.
Wired
2026-10-02
Vulnerability disclosed
Objective-See Foundation reported the vulnerability in the ChatGPT macOS app, detailing how it could be exploited to access sensitive user data.
Forklog

More articles in this cluster (2)

Following this threat?

Track Meta and CVE-2026-100754 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2026-100754?
CVE-2026-100754 is a vulnerability in the ChatGPT macOS app that allows unprivileged code to impersonate trusted components, potentially accessing user conversations.
How was the vulnerability exploited?
The vulnerability was exploited by bypassing trust verification through a script interpreter that could execute untrusted code.
What should users do now?
Users should ensure they have updated to the latest version of the ChatGPT macOS app to mitigate the risk associated with this vulnerability.