Oossa

OpenAI patches Mac ChatGPT app vulnerability

A bug in the macOS ChatGPT client could let attackers read chats and run commands; OpenAI fixed it after a report on Sep 25, 2026.

OossaPublished by Oossa: 1 min read

Giorgio Trovato · Unsplash

A security flaw in OpenAI’s ChatGPT app for macOS was patched after researchers showed it could let a hacker take over the program on a user’s computer. The bug let an attacker read all stored chat logs and launch commands that appeared to come from the legitimate app, such as opening a browser session. OpenAI listed the fix in its change log on September 25, 2026.

How the bug worked

The app uses several layers of digital‑signature checks to verify that internal components are authentic. Researchers at the Objective‑See Foundation found a trusted script interpreter that accepted untrusted scripts. By spawning this interpreter three times, a malicious script could satisfy the signature checks and slip into the main ChatGPT process. The proof‑of‑concept needed only about a dozen lines of code.

Why it matters

If the vulnerability had been exploited, an attacker could see private conversations and use the app to control other software on the Mac. OpenAI says it is working to speed up security updates, but the incident shows that AI tools with deep system access can become attractive targets.

Why it matters

For everyday Mac users, the patch means their ChatGPT conversations are no longer exposed to a simple script attack. It also highlights that AI apps can be a gateway for malware, so keeping software up to date remains essential.

Was this article useful?
Share

Read next

Oossa · Newsletter

The week in AI, explained

Every Monday: the stories worth knowing, in plain language. Free, no spam.