
ChatGPT open on a phone in front of a MacBook (illustrative). Image: Jernej Furman / Wikimedia Commons, CC BY 2.0, cropped
OpenAI has fixed a security flaw in the ChatGPT app for Mac that could have let a malicious program on the same computer take over the app, read every saved chat and send commands that looked as if they came from ChatGPT itself. Security researcher Patrick Wardle, who found it, told Wired it was “insanely trivial” to exploit.
OpenAI’s changelog lists the fix as a macOS security update on September 25: it “fixed CVE-2026-100754 on macOS in version 26.924.20706, with thanks to Patrick Wardle, Objective-See Foundation.” Anyone using ChatGPT on a Mac should make sure the app is on that version or later.
How the attack worked
The Mac app is made up of several components that talk to each other. To stop outside software from sneaking in requests, each component checks the digital signature of whatever is calling it, and the app goes as far as checking three levels up the chain of processes, so a malicious program can’t simply use an OpenAI component as a go-between.
Wardle, a longtime macOS researcher at the Objective-See Foundation, found a gap. One trusted part of the app, a script interpreter, would accept a script from an untrusted source and pass it into the main ChatGPT process. “They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements,” he told Wired.
His proof of concept took about a dozen lines of code. With it, an attacker’s program could read ChatGPT’s chat logs and other stored data, and get ChatGPT to run commands for it, such as opening a browser or other sensitive apps, with the requests appearing to be legitimate instructions from OpenAI’s own software. It needed code already running on the victim’s Mac, so it was a way to escalate an existing infection rather than a remote break-in.
OpenAI spokesperson Shane Bauer told Wired: “We continue to evolve our security practices, but recognize a need to move faster.”
“The building manager who has access to the keys to all the rooms”
Wardle’s point is less about one bug than about what AI assistants on the desktop now hold. To be useful, they are connected to browsers, files and other apps, which makes them a prize for attackers:
Agents need a lot of access to do their job. They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that’s super problematic.
Patrick Wardle, Objective-See Foundation, to Wired
He has also found a now-patched flaw in the dictation feature of Meta’s Muse assistant, which a local attacker could have used to grab a mishandled login token and get at user data, and he told Wired he has already sent OpenAI a new report about how ChatGPT connects to its always-on dots agents, launched at DevDay on Tuesday. OpenAI is reviewing it.
Wardle plans to present his research on a number of AI app bugs on macOS at Objective by the Sea, an Apple-focused security conference, in November.
Features first, security later?
The fix lands in a week when most AI security news has been about agents behaving badly on their own, from the more than 100 organisations OpenAI has warned about its agents’ activity to Muse sharing a user’s home address with a stranger. Wardle’s finding is the more old-fashioned risk: the apps themselves can be broken into.
AI companies are fixated on adding features right now. But as always, the more features, the broader the attack surface.
Patrick Wardle, to Wired
He added that security “still often seems like an afterthought” at the companies he has looked at.
Why it matters
Desktop AI assistants are being given the run of people’s computers, so a flaw in one is a flaw with access to everything it can touch. This bug is fixed, but with OpenAI and Meta racing to ship always-on agents, and a new report already sitting with OpenAI, update the app and expect more of these.
Sources: OpenAI ChatGPT and Codex changelog (macOS security update, September 25, 2026); Wired (Wardle and OpenAI statements).


