ChatGPT for macOS Vulnerability Could Let Attackers Hijack the AI App
AI tools are increasingly trusted with access to sensitive data and other applications. While reports of AI agents autonomously hacking websites or being used by cybercriminals remain uncommon, a recently patched vulnerability in OpenAI’s ChatGPT macOS app highlights the risks of compromising the AI software itself.
An attacker exploiting the flaw could effectively hijack ChatGPT on a victim’s Mac, gaining access to browser sessions, chat logs and other data stored by the app. Researchers at the Objective-See Foundation said the vulnerability demonstrates how much system access and user trust AI platforms may receive—and why those platforms could become attractive targets.
ChatGPT’s Extensive System Access Creates Security Risks
“Agents need a lot of access to do their job,” says Patrick Wardle, a software analyst at the Objective-See Foundation and a longtime macOS researcher. “They’re like building managers who have access to all the room keys. So if they can be damaged or destroyed, that’s a huge problem. That means unprivileged code could potentially access everything.”
OpenAI recognized the issue in its release notes. OpenAI spokesperson Shane Bauer told WIRED in a statement, “While we continue to evolve our security practices, we recognize the need to move faster.”
How the ChatGPT macOS Vulnerability Worked
The ChatGPT macOS app contains multiple components that communicate securely by checking digital signatures. These checks are designed to confirm that both processes belong to OpenAI rather than to external or potentially malicious software. The system uses three layers of signature checks to prevent malicious programs from directing OpenAI components to act as a trusted proxy.
However, Objective-See Foundation researchers found that a trusted component—the script interpreter—could be manipulated into accepting an untrusted script or a list of commands and passing them to the main ChatGPT process.
“They also check the parents and grandparents of that process, but the malicious script just spawns the script interpreter three times and makes requests to meet the requirements,” Wardle said.
The vulnerability could only be exploited by an attacker who had already installed malware on the target Mac. Wardle said exploiting the flaw was “very easy” and required only about a dozen lines of code for the proof of concept.
What Attackers Could Access Through ChatGPT
Beyond accessing ChatGPT chat logs, an attacker could use the vulnerability to make the app execute commands on their behalf. Those commands could include accessing browsers and other sensitive applications while making the activity appear to be legitimate instructions from OpenAI software.
OpenAI’s response underscores the security challenge facing AI applications: the more access an agent receives to perform useful tasks, the greater the potential impact if that agent or one of its trusted components is compromised.
Source: www.wired.com


