AI plugin for Apple Messages raises privacy alarms as it scans old chats without all participants' consent
OpenAI's new plugin for ChatGPT on Mac allows the chatbot to search and summarize iMessage conversations, but only the installer needs to grant permission. Security experts warn that this could expose private communications to AI without the knowledge of other participants. The plugin runs locally and only reads messages when explicitly asked, but critics compare it to spyware for those who rely on encrypted messaging.
The plugin requires users to manually enable it and grant three separate macOS permissions—AppleScript, Accessibility, and Full Disk Access—before it can interact with Messages. OpenAI states the tool operates locally, does not build a searchable index, and only accesses conversations when a user makes a specific request. The company also notes that no message history is automatically uploaded.
Security experts point out that end-to-end encryption remains technically unbroken; the concern lies in what happens after decryption on the recipient's device. Lookout's CTO acknowledges the spyware comparison is somewhat strong, since the feature is off by default and requires explicit consent, but he still views the integration as introducing significant risk to a channel many consider secure.
This development could reshape expectations around digital privacy, as one person's choice to enable the plugin may expose others' words to AI analysis without their knowledge. People in sensitive professions—journalists, lawyers, activists—may find their encrypted conversations compromised by a contact's decision. The feature could also erode trust in messaging platforms generally, as users can no longer assume their words stay within the conversation.