Security researcher Patrick Wardle has a habit of finding the softest spot in Apple-ecosystem software, and his latest target was one of the most scrutinized desktop apps in the world. In findings reported by WIRED, Wardle's team at the Objective-See Foundation discovered a vulnerability in ChatGPT's macOS app that let code already running on a Mac bypass the app's trust checks and issue commands to its main process — as if the commands came from OpenAI itself.
The bug, tracked as CVE-2026-100754, was fixed on September 25 and is addressed in app version 26.924.20706, per OpenAI's changelog. But the mechanics are worth understanding, because they illustrate a problem bigger than one app. ChatGPT for Mac is built from multiple processes that verify each other's digital signatures before communicating, and the checks extend to ancestry: a request's parent and grandparent processes are inspected to distinguish OpenAI software from everything else.
The weak link was a trusted script interpreter that accepted untrusted commands. Wardle told WIRED the malicious code simply launched the interpreter three times, which satisfied the ancestry checks and made the request appear legitimate. His proof of concept took about a dozen lines of code — "insanely trivial," in his words. Once inside, the code could read chats and other data stored by the app, and ask ChatGPT to run commands for the attacker, including interacting with the browser. The attack required malware already on the machine; it was not a remote exploit. But on a compromised Mac, it meant an untrusted program could borrow ChatGPT's privileges to reach resources it could not otherwise touch.
The timing lands awkwardly for the entire desktop-agent category. The same trust-chain question surfaced this week when a researcher reported a separate flaw in how ChatGPT connects to OpenAI's new always-on Dots assistant, and when Apple announced — in a post that read like a direct response to the Meta Muse privacy storm — that it will require much more explicit user action before granting Full Disk Access. ChatGPT for Mac, notably, offers Apple Messages integration that depends on exactly that permission.
Wardle's analogy is the building manager who holds keys to every room: if someone can manipulate the manager, everything entrusted to the building becomes reachable. Desktop assistants are, by design, building managers. They read files, send messages, and act on the user's behalf — which means their process architecture, not just their model behavior, is now part of the attack surface.
OpenAI said it continues to improve its security practices while acknowledging it needs to move faster. Wardle, for his part, is not done: he has submitted another vulnerability report to OpenAI, this one concerning the integration between ChatGPT and the Codex assistant, which the company is reviewing. In November he will present analysis of several bugs in macOS AI apps at the security conference Objective by the Sea. The message to every lab shipping an agent is fairly clear — your app's privilege model will be audited by people who read check-raising code for breakfast, and "insanely trivial" is a grade you do not want to receive.
Comments (0)
Log in to join the discussion
Log InNo comments yet