A flaw in the ChatGPT Mac app let an attacker with prior access beat three layers of OpenAI's code signing checks and reach stored chats and browser sessions.
A trusted script interpreter inside OpenAI's ChatGPT app for Mac could be tricked into accepting an untrusted script by spawning itself three times. Each layer of the app's three-stage signature check still saw an OpenAI-signed parent, so the request slipped into the main ChatGPT process. An attacker with a foothold on the machine could then read stored chats and ride active browser sessions.
The flaw was found by researchers at the Objective-See Foundation, a nonprofit Mac security group, and disclosed to OpenAI in advance. The company patched it and acknowledged it publicly in its system change log on September 25.
"Agents need a lot of access to do their job," Objective-See's Patrick Wardle told WIRED. "They are like the building manager who has access to the keys to all the rooms. So if they can be corrupted or subverted, that's super problematic. It can mean that unprivileged code could then potentially have access to all the things."
OpenAI spokesperson Shane Bauer told WIRED: "We continue to evolve our security practices, but recognize a need to move faster."
The exploit required a prior foothold on the target Mac, so it was not a remote compromise. OpenAI has not published a CVE identifier or the full affected version range; the patch was logged on September 25.