A broken trust check opened ChatGPT Mac app to local code

A flaw in OpenAI's ChatGPT app for macOS let ordinary programs pose as trusted components and reach the data the assistant already held.

AppleThreat Staff
2 Min Read

A desktop AI assistant that already holds broad permissions on a Mac makes an inviting target: compromise one of its parts and the attacker inherits everything the app can reach. A now-patched flaw in one of the most widely used assistants showed how thin the wall between trusted and untrusted code can be.

The bug lived in OpenAI’s ChatGPT app for macOS and is catalogd as CVE-2026-100754. Researchers at the Objective-See Foundation reported it, and the fix shipped in app version 26.924.20706.

The app’s components establish trust by checking digital signatures, a way to separate OpenAI’s own processes from outside software. That check did not stop at the process making a request: it also vouched for its parent and grandparent, drawing a wider circle of code into the trusted ring. Inside sat a script interpreter able to run code the app had never vetted, and calling it three times in a row let the main process read an attacker’s request as if it came from an OpenAI component. From there, local code could read conversation history, drive connected integrations and, in effect, borrow the app’s permissions, though only within what the user had already granted, such as a browser or a messaging integration.

Requests looked ordinary to macOS, which is what made the gap matter for anyone running an agent with broad access. OpenAI’s Shane Bauer told WIRED the company keeps sharpening its security practices but accepted it needs to move faster, and the finding lands in a year that already saw an April supply-chain incident force OpenAI to revoke a macOS certificate.

Share This Article