NEWS · COMPANIES · #1432
Patched vulnerability in ChatGPT macOS app could have allowed full takeover
Researchers at the Objective‑See Foundation disclosed a recently patched vulnerability in OpenAI’s ChatGPT macOS app that could have allowed an attacker to run arbitrary commands and access chat logs and other data by abusing a trusted script interpreter. OpenAI acknowledged the issue in its system changelog on September 25; the researcher Patrick Wardle says the exploit was trivial and he will present related macOS AI app analyses at the Objective by the Sea conference.
KEY POINTS
- Researchers at the Objective‑See Foundation disclosed a recently patched vulnerability in OpenAI’s ChatGPT macOS app that could have allowed an attacker to run arbitrary commands and access chat logs and other data by abusing a trusted script interpreter.
- OpenAI acknowledged the issue in its system changelog on September 25; the researcher Patrick Wardle says the exploit was trivial and he will present related macOS AI app analyses at the Objective by the Sea conference.
- Because AI client apps often require deep system access, vulnerabilities in them can let attackers fully compromise user data and other applications.
WHY IT MATTERS
Because AI client apps often require deep system access, vulnerabilities in them can let attackers fully compromise user data and other applications.