A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
Oct 2, 2026, 2:45 AM · WIRED

Objective-See found a trivial macOS ChatGPT trust bypass — chat logs, browser hooks, and “run this for me” — while labs race agents that need the keys to every room.
Why it matters
WIRED reports a patched vulnerability in OpenAI’s ChatGPT macOS app discovered by Objective-See Foundation researchers. The bug could let an attacker take over the app locally: read chat logs and other stored data, hitch rides on browser sessions, and coerce ChatGPT into running commands that look like legitimate OpenAI instructions.
OpenAI acknowledged the fix in its September 25 changelog. Spokesperson Shane Bauer said the company is evolving security practices but “recognize[s] a need to move faster.” Researcher Patrick Wardle called the exploit “insanely trivial” — roughly a dozen lines of code — by nesting a script interpreter so parent/grandparent signature checks passed.
From the desk
We’ve been covering agents that hack outward. This story is the mirror: AI clients are high-value local malware targets because they already hold the building manager’s keys. Wardle’s framing is right. If the assistant needs deep system trust to be useful, subverting that trust is catastrophic.
OpenAI’s “move faster” line lands poorly next to a dozen-line PoC. Feature velocity on Dots-style always-on assistants expands the same surface Wardle is already poking — he says he’s filed another report on ChatGPT’s integration with the new Dots assistant, and he recently patched a Muse dictation token mishandling at Meta.
Useful AI on the desktop is worth defending. That means treating client security like the product, not an afterthought to DevDay demos. I’m watching whether labs staff macOS/Windows hardening at the same tempo as agent features — and whether Wardle’s November Objective by the Sea talk forces a wider audit wave.
Context
The piece lands amid a stretch of agent escape and hacking headlines. The strategic point is less “AI is dangerous code” than “AI apps are privileged software with chat-history gold.”
Who feels it
- ChatGPT desktop users
- Patch promptly; assume local malware that can talk to a trusted AI process is a data-exfil path, not a curiosity.
- AI platform security teams
- Multi-layer signature checks that still accept nested script interpreters are a process smell — threat-model the helper processes.
- Enterprises rolling out agents
- Endpoint controls and least-privilege for AI clients matter as much as model alignment slides.
What to watch
- OpenAI’s response to Wardle’s newer Dots-integration report
- Whether other major AI desktop apps get similar public audits
- Enterprise guidance treating AI clients as high-sensitivity apps
Companies: OpenAI