344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth193
AI Infrastructure & MLOps175
Writing & Content Creation204
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Researchers found a bug in ChatGPT for macOS that could have let attackers access chat logs and run commands. OpenAI says it fixed the issue.
In short: OpenAI patched a flaw in the ChatGPT app for macOS that could have let hackers access a user’s chats and other sensitive data.
Security researchers at the Objective-See Foundation found a vulnerability, meaning a security weakness, in the Mac version of OpenAI’s ChatGPT app. They said an attacker could have used it to take control of the app on someone’s computer.
If exploited, the bug could have given an attacker access to ChatGPT chat logs and other data stored by the app. The researchers also warned it could have allowed the attacker to make ChatGPT run commands, like reaching into a web browser session. In simple terms, it could have been like getting the “keys” to parts of your computer that the ChatGPT app is trusted to access.
OpenAI acknowledged the issue and a fix in its change log on September 25. An OpenAI spokesperson told WIRED the company is working on improving its security practices and needs to move faster.
The researchers said the app uses digital signature checks, which are like checking an ID badge to confirm software parts really belong to OpenAI. But they found a trusted component that could be tricked into accepting untrusted instructions. Researcher Patrick Wardle said the workaround was easy to pull off and his demo took about a dozen lines of code.
AI apps often need broad access to work, especially tools that connect to other apps. That makes them useful, but it also makes them an appealing target. If you use the ChatGPT app on a Mac, it is a reminder to keep apps updated, since security fixes often come through regular updates.
Source: Wired