Flaw in OpenAI's ChatGPT macOS app could have let attackers take over the app and access chat logs
Researchers at the Objective-See Foundation found a vulnerability in the macOS version of OpenAI's ChatGPT. It could have let an attacker take over the app, access chat logs and other stored data, and get ChatGPT to run commands such as accessing a browser. The flaw could only be exploited by an attacker who already had malware on the target machine. OpenAI acknowledged the flaw and its fix in its system change log on September 25.
What the AI did
The ChatGPT app for Mac computers contained a security flaw that could have let an attacker take over the app, read its chat logs and other stored data, and get ChatGPT to run commands such as accessing a browser. The attacker would already have needed malicious software installed on the machine. OpenAI has since fixed the flaw.
First reported September 25, 2026 · Added to the register October 7, 2026 · 1 source
- Developer
- OpenAI
- Model
- ChatGPT macOS app
- When it happened
- Not stated in the sources
- First reported
- September 25, 2026
What this means for you
Could this affect you?
Users of the ChatGPT macOS app whose computers were already infected with malicious software could have had their chat logs, stored data and connected browser sessions exposed before the fix.
What to check
- Update the ChatGPT macOS app to the patched version.
- Treat AI desktop assistants as high-privilege software in device security reviews.
- Limit the access that AI desktop assistants are granted.
Areas of your AI programme this touches
Every fact and its source (5)
- Discovered byObjective-See Foundation researchers“Discovered by researchers at the Objective-See Foundation”[1]
- Potential impactAccess to chat logs, stored data and browser sessions“giving an attacker access to all the chat logs and other data stored by the app, as well as interconnections like browser sessions”[1]
- Exploit preconditionAttacker needed malware already installed“The flaw could only be exploited by an attacker who already had malware installed on a target machine.”[1]
- Company responseOpenAI acknowledged the flaw and fix in its change log“OpenAI publicly acknowledged the security flaw and fix in its system change log on September 25.”[1]
- Proof of concept sizeAbout a dozen lines of code“his proof of concept only required about a dozen lines of code”[1]
Sources
- A Flaw in ChatGPT's Mac App Could Have Let Hackers Grab Sensitive Datawired.com · October 2, 2026
How this record is classified. Severity N: a legal action or test finding, not a harm. OECD level: hazard, an event that could plausibly have led to harm. Evidence: Confirmed, meaning a company, official or court statement.
The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and checked against them automatically before publication. Records reflect what has been disclosed, not everything that has happened. Incidents are found through news feeds and the GDELT Project.
