Full Report
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting—and vulnerable—target.
Analysis Summary
# Vulnerability: OpenAI ChatGPT macOS Data Exposure via Excessive Permissions
## CVE Details
- **CVE ID:** Not explicitly listed in the provided text (Historically associated with researchers at Objective-See Foundation).
- **CVSS Score:** N/A (Severity categorized as High/Critical based on context of full account takeover).
- **CWE:** CWE-284: Improper Access Control / CWE-269: Improper Privilege Management.
## Affected Systems
- **Products:** OpenAI ChatGPT Desktop Application for macOS.
- **Versions:** Versions prior to the October 2026 patch cycle.
- **Configurations:** Systems where the ChatGPT app is installed and granted deep system access (e.g., accessibility permissions, browser interconnections).
## Vulnerability Description
The vulnerability stems from the deep system access and elevated permissions granted to the ChatGPT macOS application to facilitate its "agentic" capabilities. Due to insufficient isolation between the application's data storage and other local processes, an attacker could bypass standard security boundaries. This flaw allowed for the unauthorized extraction of sensitive data, including local chat history logs and active session tokens from interconnected browsers used by the AI agent.
## Exploitation
- **Status:** Patched (PoC confirmed by Objective-See Foundation researchers).
- **Complexity:** Medium.
- **Attack Vector:** Local (Requires initial access to the victim's macOS environment to interact with the application’s stored data or interconnected sessions).
## Impact
- **Confidentiality:** High (Full access to private chat logs, personal data, and browser session information).
- **Integrity:** Medium (Potential to manipulate chat history or session data).
- **Availability:** Low (Primary impact is data theft rather than service disruption).
## Remediation
### Patches
- **OpenAI Update:** Users should update the ChatGPT macOS application to the latest version via the official OpenAI website or the in-app update prompt. The vulnerability was confirmed as "recently patched" as of October 2026.
### Workarounds
- **Permissions Review:** Users can revoke unnecessary system permissions (such as Accessibility or Screen Recording) in macOS System Settings, though this may degrade the application's functionality.
- **Session Management:** Periodically clearing chat history and logging out of the application when not in use.
## Detection
- **Indicators of Compromise:** Unusual file access patterns to the ChatGPT application's support folders (e.g., `~/Library/Application Support/com.openai.chat`).
- **Detection Methods:** Security software monitoring for unauthorized access to ChatGPT-related databases and session cache files.
## References
- **Vendor Advisory:** OpenAI Security Portal (Defanged: hxxps[://]openai[.]com/security)
- **Researcher Report:** Objective-See Foundation (Defanged: hxxps[://]objective-see[.]org)
- **Original Article:** WIRED (Defanged: hxxps[://]www[.]wired[.]com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-data/)