A reported vulnerability in ChatGPT for macOS could have let an attacker route an untrusted script into the app’s main process, potentially exposing chat logs and other stored data. Researchers at Objective-See Foundation reportedly identified the flaw, and Patrick Wardle described how a script interpreter could pass the app’s process checks. OpenAI reportedly acknowledged and fixed the issue on September 25, 2026.
What the reported flaw could have allowed
The potential impact included access to ChatGPT chat logs and other data stored by the app. An attacker could also have used the app to issue commands that reached a browser or other sensitive applications.
How the process-check bypass worked
The app’s components used digital-signature checks, and its process checks looked at a process’s ancestry: the process itself, its parent and its grandparent. A trusted script interpreter could accept an untrusted script and pass it into ChatGPT’s main process, according to Patrick Wardle’s explanation of the reported flaw.
The described bypass involved launching the interpreter three times before making the request. That process chain could satisfy checks of the process, its parent and its grandparent. Wardle estimated that a proof of concept took about a dozen lines of code.
OpenAI’s reported fix
OpenAI reportedly acknowledged and fixed the vulnerability on September 25, 2026.