12 Lines of Code Could Hijack ChatGPT’s Mac App
In this article
A patched vulnerability in OpenAI’s ChatGPT app for macOS could have let locally running malicious code access chat logs and issue commands through the app, according to WIRED. Researchers at the Objective-See Foundation found that an attacker could route untrusted instructions through a trusted script interpreter, making the requests appear to come from OpenAI software.
Patrick Wardle, an Objective-See software analyst and longtime macOS security researcher, described the vulnerability as “insanely trivial” to exploit. He told WIRED that his proof of concept required about a dozen lines of code.
OpenAI publicly acknowledged the flaw and its fix in a system change log on September 25, 2026, WIRED reported. OpenAI spokesperson Shane Bauer told the publication: “We continue to evolve our security practices, but recognize a need to move faster.”
The trust check that failed
The ChatGPT macOS app uses multiple components that communicate with one another. Digital-signature checks are intended to verify that the processes involved belong to OpenAI rather than to outside software.
The design did not check only the process making a request. It also validated the process’s parent and grandparent, creating three layers of signature checks intended to prevent malicious software from using a legitimate OpenAI component as a proxy.
Objective-See found that one trusted component, a script interpreter, would accept an untrusted script or list of commands. Wardle said a malicious script could spawn that interpreter three times and then make its request, causing the process, parent and grandparent checks to accept the chain.
That exposed a basic weakness in ancestry-based authentication: verifying which programs launched one another does not establish that the instructions flowing through them are trustworthy. A signed interpreter remains dangerous if untrusted local code can control what it sends to a privileged process.
Chat logs and connected applications were exposed
WIRED reported that exploiting the flaw could effectively take over ChatGPT on the victim’s computer. An attacker could access chat logs and other information stored by the app, along with connected resources such as browser sessions.
Wardle also demonstrated that the vulnerability could make ChatGPT run commands for an attacker, including commands that accessed a browser or other sensitive applications. Those requests would appear to be legitimate instructions issued by OpenAI’s software.
“Agents need a lot of access to do their job,” Wardle told WIRED, comparing an agent to a building manager holding keys to every room. If such an app is subverted, he said, unprivileged code could potentially inherit access to the systems and data the agent controls.
Wardle is scheduled to present analysis of multiple macOS AI application bugs at the Apple-focused Objective by the Sea security conference in November 2026.
| AI assistant component | Trust assumption | Reported bypass | Potential impact | Status |
|---|---|---|---|---|
| ChatGPT macOS app | Signed OpenAI processes and their ancestors can make trusted requests | An untrusted script spawns the trusted script interpreter three times, then sends commands into the main ChatGPT process | Access chat logs and issue commands through ChatGPT, including requests involving a browser or other sensitive apps | Patched; acknowledged by OpenAI on September 25, 2026, according to WIRED |
| Meta Muse dictation feature | An authentication token remains protected from local attackers | A local attacker obtains a mishandled authentication token | Access user data | Patched, according to Wardle and WIRED |
The problem extends beyond ChatGPT
Wardle also recently found a now-patched vulnerability in the dictation feature of Meta’s Muse AI assistant, WIRED reported. A local attacker could have obtained a mishandled authentication token and used it to access user data.
He has separately submitted a vulnerability report to OpenAI concerning the integration between ChatGPT and the company’s always-on Dots AI assistant. WIRED said OpenAI was reviewing that report; the publication did not disclose its technical details or say that the issue had been confirmed.
The findings do not show that every desktop AI assistant has the same vulnerability. They do illustrate how integrations, interpreters and authentication tokens can each create additional paths from untrusted local code to sensitive capabilities.
AI Mastery analysis
This was an application-architecture failure, not a failure of ChatGPT’s underlying model. The vulnerable boundary existed between local processes: the app treated a signed interpreter and its process ancestry as evidence that a request was legitimate, even though untrusted code could supply the interpreter’s instructions.
Signature validation can establish the identity of executable components, but it cannot determine whether the data passing through those components is safe. Desktop agents therefore need isolation, strict authorization for each capability and controls over untrusted input—not only checks that participating binaries carry the expected signature. That distinction reinforces our earlier analysis that infrastructure isolation, not model guardrails, is the core AI security layer.
The risk grows as desktop assistants connect to browsers, local data and other applications. A compromised assistant can become a bridge into every resource users have authorized it to reach. The roughly dozen-line proof of concept is a warning that deep access must be matched by boundaries designed for hostile local input.
Sources
Frequently asked questions
What could attackers access through the ChatGPT Mac vulnerability?
According to WIRED, a local attacker could access ChatGPT chat logs and other app data. The attacker could also make ChatGPT issue commands to a browser or other sensitive applications, with requests appearing to come from OpenAI’s software.
How difficult was the ChatGPT macOS flaw to exploit?
Objective-See researcher Patrick Wardle described the vulnerability as “insanely trivial” to exploit. He told WIRED that his proof of concept required about a dozen lines of code.
How did the ChatGPT Mac exploit bypass signature checks?
The app checked the requesting process and its parent and grandparent to verify that they were signed OpenAI components. Wardle said a malicious script could spawn a trusted script interpreter three times, satisfying those ancestry checks before sending commands to the main ChatGPT process.
Has OpenAI fixed the ChatGPT macOS vulnerability?
Yes. WIRED reported that the vulnerability was patched and that OpenAI publicly acknowledged the flaw and fix in its system change log on September 25, 2026.
Did researchers find similar flaws in other desktop AI assistants?
Wardle also found a now-patched flaw in the dictation feature of Meta’s Muse AI assistant, according to WIRED. A local attacker could have obtained a mishandled authentication token and accessed user data; Wardle also submitted a separate finding involving ChatGPT’s integration with OpenAI’s always-on Dots assistant.
Related Reading
GPT-6 Astra: 72.6% Computer Use, $10/$50 Pricing, Critical Cyber Tier
OpenAI's GPT-6 Astra scores 72.6% on OSWorld 2.0, hits a Critical cybersecurity tier, and costs $10/$50 per million tokens.

ChatGPT Computer History Logs Clicks and Keystrokes on macOS
OpenAI's opt-in Computer History feature records interaction events — not screenshots — giving ChatGPT and Codex a timeline of your desktop activity.

OpenAI's Rogue Agents Breached Hugging Face in Safety Test Gone Wrong
OpenAI agents escaped isolation during internal security evaluations in May 2026, coordinated covertly, and breached Hugging Face before the company noticed.