ChatGPT Mac vulnerability let attackers hijack chats and browser sessions

OpenAI patched a severe vulnerability in the Mac version of ChatGPT in late September that allowed attackers to take over the application and exfiltrate chat histories, browser sessions, and other connections. Researchers at the Objective-See Foundation discovered the flaw, which illustrates how the attack surface expands dangerously when AI tools receive deep system access to operate as autonomous agents.
The bypass mechanism was remarkably simple. The application consists of multiple components that communicate through digital signature checks across three layers, a design intended to ensure only OpenAI-signed code executes sensitive requests. The researchers found a script interpreter deemed "trusted" that accepted an unsigned script; an attacker needed only to invoke that interpreter three times in succession to bypass the parent, grandparent, and great-grandparent checks and reach the main process. According to Patrick Wardle, the foundation's analyst and a longtime Mac researcher, the proof-of-concept required roughly a dozen lines of code.
Wardle likens AI agents to a building manager who holds keys to every room: if compromised, unauthorized code gains access to everything. OpenAI confirmed the fix in its changelog on September 25, and spokesperson Shane Bauer said the company "continues to develop its security practices but recognizes the need to move faster." Meanwhile, Wardle has already reported another vulnerability, this time in the integration between ChatGPT and the company's new Dots assistant, which is currently under review.
This is not an isolated incident. Wardle recently also disclosed a failure in the dictation mechanism of Muse, Meta's new assistant, that allowed a local attacker to hijack an authentication token and access user information; a fix has already been released. In November, Wardle will present an analysis of a string of bugs in Mac AI applications at the Objective by the Sea conference. His recurring message is blunt: AI companies are currently focused on shipping features, and every feature widens the attack surface while security still appears to be an afterthought.