OpenAI patched a ChatGPT for Mac flaw that exposed chats and browser sessions
OpenAI patched a macOS ChatGPT vulnerability on 25 September after Objective-See Foundation researchers found a script interpreter that could pass untrusted code to the main app. The flaw could expose chat histories and active browser sessions, and researchers said exploiting it took just over 10 lines of code.
Bottom line — OpenAI says the Mac vulnerability is patched; the report highlights the security risks of software with broad system access.
Go deeper 6
-
Mezha, citing Wired, reports that the flaw could also let attackers run commands as ChatGPT and access browsers or other applications.
-
Objective-See Foundation researchers said the app’s security checks did not prevent the vulnerable interpreter from forwarding untrusted scripts.
-
OpenAI acknowledged the vulnerability and said it was patched on 25 September, according to Mezha.
-
A separate OpenAI feature, Computer History, creates local activity memories from selected apps and websites; Kagi says it is off by default and excludes screenshots and audio.
-
OpenAI’s Computer History documentation warns that its memory files are unencrypted and that the feature increases prompt-injection risk, according to Kagi.
-
OpenAI’s Help Center says users can review active sessions and log out of individual sessions or all sessions; logging out everywhere may take up to 30 minutes.