Patched ChatGPT Mac Flaw Could Expose Chat Logs to Attackers
A dozen lines of code could bypass signature checks and read chat logs; the flaw is fixed, but the attack surface of desktop AI apps deserves continued attention.
A vulnerability in the ChatGPT macOS app that could expose chat logs has been patched, with OpenAI confirming the fix in its change log on September 25.
Patrick Wardle, a researcher at the macOS security nonprofit Objective-See Foundation, found that a trusted script interpreter inside the app would accept an untrusted script; spawning it three times satisfied OpenAI's three-layer signature checks. Wardle called the exploit "insanely trivial," requiring only about a dozen lines of code.
An attacker could read all chat logs and have ChatGPT run commands on their behalf, such as accessing the browser, with requests appearing as legitimate OpenAI instructions. Wardle will present analysis of multiple AI macOS app bugs at the Objective by the Sea conference in November, and says he has already submitted a new report to OpenAI concerning the integration with its new Dots assistant.
Sources:https://www.wired.com/story/a-flaw-in-chatgpts-mac-app-could-have-let-hackers-grab-sensitive-datahttps://learn.chatgpt.com/docs/changelog