A 12-line exploit could have hijacked ChatGPT on macOS
A trivial bug in OpenAI’s ChatGPT macOS app, disclosed September 25, could have let attackers hijack the chatbot with about twelve lines of code and steal chat logs and browser sessions.

Updated
Why it matters
- OpenAI disclosed the ChatGPT macOS vulnerability and its fix in its system change log on September 25.
- The flaw was exploitable with a proof of concept of roughly a dozen lines of code, according to Patrick Wardle.
- An attacker who triggered the bug could read ChatGPT chat logs and reach active browser sessions on the victim’s Mac.
- Researcher Patrick Wardle plans to present additional AI macOS application bugs at the Apple-focused conference Objective by the Sea in November.
- Wardle has also submitted a separate vulnerability report to OpenAI involving the integration between ChatGPT and the company’s Dots AI assistant.
A vulnerability in OpenAI’s ChatGPT macOS app, disclosed on September 25, could have been exploited with roughly a dozen lines of code to take over the chatbot on a victim’s machine and read every stored conversation. The bug, discovered by researchers at the Objective-See Foundation, underscores the security exposure that comes with installing AI assistants deep into a computer’s operating system.
OpenAI has patched the flaw. The disclosure lands at a moment when AI tools are moving from the browser into standalone desktop apps with broad system privileges, giving attackers a new class of high-value targets.
What exactly could an attacker do?
The exploit chain would have granted a malicious program the ability to:
- Read ChatGPT chat logs and other data stored by the desktop app
- Reach into interconnections like active browser sessions
- Issue commands through ChatGPT that the app would treat as legitimate OpenAI instructions, including reaching into other sensitive applications
“Agents need a lot of access to do their job,” Patrick Wardle, a software analyst at the Objective-See Foundation and longtime macOS security researcher, told me. “They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that’s super problematic. It can mean that unprivileged code could then potentially have access to all the things.”
The vulnerability was, in Wardle’s words, “insanely trivial” to exploit. His proof of concept required about twelve lines of code.
How did the macOS app fall for it?
The ChatGPT macOS app is built from several components that verify one another through digital signature checks. The design aims to confirm that any process making a request is genuinely an OpenAI component, not outside malware, and it extends those checks three layers up the process tree to stop a malicious program from spawning a trusted binary as a proxy.
Objective-See found a gap in that chain. A trusted script interpreter inside the ChatGPT package would accept an untrusted script and could be steered into feeding that script into the main ChatGPT process.
Wardle explained how the trust check was defeated. “They also check the parent and grandparent of that process, but the malicious script just spawns the script interpreter three times and then makes the request so it will satisfy the requirements,” he said.
The result: a request that looked legitimate to ChatGPT, originating from a process tree that satisfied every signature check, but actually carrying attacker-supplied code.
What did OpenAI say?
OpenAI acknowledged the issue and the fix in its system change log on September 25. A company spokesperson addressed the broader pattern of disclosure.
“We continue to evolve our security practices, but recognize a need to move faster,” OpenAI spokesperson Shane Bauer told WIRED in a statement.
The acknowledgment came with no dispute over Wardle’s technical write-up, and OpenAI has since confirmed it is reviewing a separate, more recent report Wardle submitted about the integration between ChatGPT and OpenAI’s always-on Dots AI assistant.
Why does this matter beyond one app?
The flaw is not just a ChatGPT bug. It is a representative example of the attack surface created when AI products are granted the kind of deep system access they need to act as agents, controlling browsers, files, and other applications on a user’s behalf.
Wardle argues the industry is not matching that exposure with a matching investment in security. “AI companies are fixated on adding features right now,” he said. “But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought.”
The pattern repeats across the field. Wardle recently found and reported a separate flaw, now patched, in the dictation feature of Meta’s new Muse AI assistant. A local attacker could have exploited it to capture a mishandled authentication token and reach user data.
He plans to present analysis of multiple AI macOS application bugs at Objective by the Sea, an Apple-focused security conference held in November.
What does the ruling change for users?
For end users, the immediate answer is: very little, as long as the ChatGPT macOS app is up to date. The patch shipped before public disclosure, and OpenAI says the issue is resolved.
The harder question is what the episode reveals about the pace of security work at companies shipping AI assistants as fast as they ship features. Wardle is not calling for less capable agents, only for the security reviews that should accompany any component entrusted with broad system privileges.
The next test of that posture arrives in November at Objective by the Sea, where Wardle will detail additional AI macOS bugs, and in OpenAI’s response to the still-pending report on Dots AI integration. Each disclosure will be a small measure of whether AI vendors treat their apps as critical infrastructure or as feature pipelines in disguise.
Original: openai.com
More from Sophie Lindqvist
Show full bio
Staff writer covering marketplaces and e-commerce at AI In Context.
195 articles