MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-02 · via Wired

Patched Security Vulnerability Exposed ChatGPT Users to Complete Account Compromise

Image via Wired
Image via Wired

Researchers discovered a critical vulnerability in OpenAI's macOS ChatGPT application that could have allowed attackers to take full control of the software and access all stored chat logs, user data, and browser sessions. The flaw involved a failure in the app's digital signature verification system, which was designed to prevent unauthorized code from communicating with legitimate OpenAI components across multiple security layers. The discovery highlights the inherent security risks posed by AI applications that require extensive system-level access to function, making them attractive targets for malicious actors.

Expanded Detail

The vulnerability operated through a weakness in how the ChatGPT application verified that different software components were legitimate before they communicated with each other. Rather than properly validating each request through multiple security checkpoints, malicious code could bypass these protections by repeatedly spawning processes in a specific sequence. Researchers demonstrated the flaw required minimal technical sophistication—just a handful of lines of code—to weaponize, though attackers would first need to establish a foothold on the target's device through other means.

This discovery reflects a broader pattern emerging across AI applications built for Apple's macOS platform. Other AI assistants, including Meta's Muse, have exhibited similar architectural weaknesses where security measures haven't kept pace with rapid feature development, according to the researchers conducting these investigations.

Context

This vulnerability could meaningfully impact ChatGPT users whose machines may already harbor malware from unrelated infections. While the threat requires existing system compromise, successful exploitation would expose sensitive conversations and potentially enable attackers to commandeer the application for unauthorized actions. The incident may prompt broader industry reconsideration of how deeply AI assistants integrate with operating systems and what security oversight accompanies such extensive system privileges, particularly as these tools become more prevalent in professional and personal workflows.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Wired →
Related stories
Third-party software flaw leads to theft of school employee records at Frontline Education · Cybersecurity
Critical Middleware Flaw in Financial and Government Systems Allows Remote Code Execution · Cybersecurity
Apple Implements Stricter Controls on Full Disk Access to Counter AI Agent Risks · Cybersecurity
Technical University of Denmark confirms large-scale data breach affecting 200,000 individuals · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “A Flaw in ChatGPT's Mac App Could Have Let Hackers Grab Sensitive Data.” Browse more stories.