A ChatGPT macOS app flaw let a local attacker read every chat and run commands as the app, patched 25 September
Wired reports that the ChatGPT macOS app had a patched flaw letting a local attacker take over the app, read every chat, and run commands through it, acknowledged by OpenAI in its change log on 25 September.

Image: Wired
Why it mattersAn AI app running with wide access to a developer's machine is itself a target, and the trust checks a team ships around its own agents can be bypassed by a trivial parent-process trick if ancestor signatures are the only control.
An AI app that sits on a developer's laptop with access to chat history, browser sessions and other local processes is a worthwhile target for an attacker in its own right. The ChatGPT macOS app had a flaw that let a local attacker take it over completely, which OpenAI acknowledged in its system change log on 25 September.
Wired reports the vulnerability, found by Patrick Wardle of the Objective-See Foundation, let the attacker read all chat logs and other data stored by the app and reach interconnections like browser sessions. The attacker could also make the ChatGPT app run commands on their behalf, with the requests appearing to come from legitimate OpenAI software.
How the trust check was defeated
The ChatGPT app is built from several components that talk to each other, and the design requires a signature check on the parent process, the grandparent process and the great-grandparent process to confirm each caller is OpenAI's own code and not an outside program posing as it. The idea is to stop malicious software from directing a trusted OpenAI component to act as a proxy for its request.
Wardle told Wired the researchers found a trusted script interpreter inside the app that would accept an untrusted script and could then deliver that script into the main ChatGPT process. "They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements," Wardle said. He called the exploit "insanely trivial" and told Wired his proof of concept "only required about a dozen lines of code".
What OpenAI said and what else is in the queue
OpenAI acknowledged the flaw and the fix in its system change log on 25 September. Spokesperson Shane Bauer told Wired, "We continue to evolve our security practices, but recognize a need to move faster." Wardle said he has already submitted another vulnerability finding to OpenAI, this one about the integration between ChatGPT and the always-on Dots AI assistant, and OpenAI is reviewing it. He also recently found and reported a patched flaw in the dictation feature of Meta's Muse AI assistant that could have let a local attacker grab a mishandled authentication token and reach user data.
If a team is building a desktop AI app and relying on parent-process checks to decide what to trust, this is the shape to watch: an ancestor-signature control cannot tell the difference between the real OpenAI software and three repeated spawns of a trusted script interpreter underneath an attacker-controlled parent. The practical move is to not grant one trusted component the authority to execute untrusted input in the first place, and to put the trust decision on the content being executed rather than on who the caller claims to be. Developers on a Mac with the ChatGPT app installed should make sure they are on the current build; the macOS app updates in-place and the fix is already shipped.
Source
Wired, A Flaw in ChatGPT's Mac App Could Have Let Hackers Grab Sensitive Data, by Lily Hay Newman and Matt Burgess, 2 October 2026.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.


