A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

AI NEWS

A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data

A critical security vulnerability in the macOS version of OpenAI's ChatGPT app allowed attackers with existing malware to hijack the application and access sensitive user data like chat logs and browser sessions. The flaw exploited a trusted script interpreter by spawning it multiple times to bypass signature checks, illustrating significant risks as AI software gains deeper system access.

THE NEWS

What happened

A critical security vulnerability in the macOS version of OpenAI's ChatGPT app allowed attackers with existing malware to hijack the application and access sensitive user data like chat logs and browser sessions. The flaw exploited a trusted script interpreter by spawning it multiple times to bypass signature checks, illustrating significant risks as AI software gains deeper system access.

CONTEXT

Why it matters

A major security vulnerability has been identified in the macOS version of OpenAI's ChatGPT app. Researchers from Objective-See Foundation discovered that an attacker with existing malware could exploit a flaw in the script interpreter to bypass security checks. This allowed them to take control of the app, access all chat logs, and execute commands on the user's machine. The issue was patched by OpenAI on September 25. Security experts warn that as AI applications require more system access to function, they become increasingly attractive targets for cybercriminals if not rigorously secured.

AT A GLANCE

Key facts

  • The vulnerability was discovered by researchers at the Objective-See Foundation.
  • An attacker with malware installed could hijack ChatGPT on a victim's Mac.
  • The flaw allowed access to chat logs, browser sessions, and execution of attacker commands.
  • OpenAI acknowledged the issue and patched it in their system change log on September 25.
  • Security analyst Patrick Wardle noted that AI agents require extensive access, making them high-value targets if compromised.
  • The exploit was described as 'insanely trivial,' requiring only about a dozen lines of code for a proof of concept.

SOURCE

Original source

This article is based on information published by WIRED AI.