A now-fixed flaw in the ChatGPT app for Mac allowed access to conversations

In 30 seconds
On September 25, OpenAI fixed a flaw in the ChatGPT app for macOS that could have let an attacker take control of the app, with access to the chat history. It was found by Patrick Wardle of the Objective-See Foundation, and version 26.924.20706 fixes it. Wardle says it was very easy to exploit.
On September 25, OpenAI fixed a vulnerability in the ChatGPT app for macOS. Its official changelog says that version 26.924.20706 fixes CVE-2026-100754, found by Patrick Wardle of the Objective-See Foundation. On October 2, WIRED published the details.
According to WIRED, the Mac app has several components that talk to each other and check digital signatures to make sure each request comes from OpenAI and not from outside software. The researchers found that one of those trusted components, a script interpreter, could accept commands and pass them to the main ChatGPT process. An attacker could have taken control of ChatGPT on the victim's computer, with access to the chat history and other app data, and made it run commands on their behalf, for example in the browser.
Wardle says exploiting it was "insanely trivial". OpenAI told WIRED that it keeps improving its security practices but recognizes the need to move faster. Wardle has also sent OpenAI another finding, related to the integration between ChatGPT and Dots, the company's new always-on agent, and OpenAI is reviewing it.
We think the practical step is simple: if your company uses ChatGPT on a Mac, check that the app is on version 26.924.20706 or later. The more permissions an AI assistant has on a computer, the more it matters to keep it up to date.
Why it matters
If you use ChatGPT on a Mac, check that the app is on version 26.924.20706 or later.
Official source: OpenAI


