Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week

A Dozen Lines of Code Could Once Command ChatGPT's Mac App: Inside the CVE-2026-100754 Exploit

A Dozen Lines of Code Could Once Command ChatGPT's Mac App: Inside the CVE-2026-100754 Exploit

A flaw in ChatGPT's macOS app, tracked as CVE-2026-100754, let code already running on a Mac hijack a trusted script interpreter to slip commands into ChatGPT's main process — potentially exposing chats and browser sessions. Objective-See's Patrick Wardle called the exploit 'insanely trivial.' OpenAI fixed it on September 25 in version 26.924.20706; Wardle has since filed another report on the Codex integration.

Security researcher Patrick Wardle has a habit of finding the softest spot in Apple-ecosystem software, and his latest target was one of the most scrutinized desktop apps in the world. In findings reported by WIRED, Wardle's team at the Objective-See Foundation discovered a vulnerability in ChatGPT's macOS app that let code already running on a Mac bypass the app's trust checks and issue commands to its main process — as if the commands came from OpenAI itself.

The bug, tracked as CVE-2026-100754, was fixed on September 25 and is addressed in app version 26.924.20706, per OpenAI's changelog. But the mechanics are worth understanding, because they illustrate a problem bigger than one app. ChatGPT for Mac is built from multiple processes that verify each other's digital signatures before communicating, and the checks extend to ancestry: a request's parent and grandparent processes are inspected to distinguish OpenAI software from everything else.

The weak link was a trusted script interpreter that accepted untrusted commands. Wardle told WIRED the malicious code simply launched the interpreter three times, which satisfied the ancestry checks and made the request appear legitimate. His proof of concept took about a dozen lines of code — "insanely trivial," in his words. Once inside, the code could read chats and other data stored by the app, and ask ChatGPT to run commands for the attacker, including interacting with the browser. The attack required malware already on the machine; it was not a remote exploit. But on a compromised Mac, it meant an untrusted program could borrow ChatGPT's privileges to reach resources it could not otherwise touch.

The timing lands awkwardly for the entire desktop-agent category. The same trust-chain question surfaced this week when a researcher reported a separate flaw in how ChatGPT connects to OpenAI's new always-on Dots assistant, and when Apple announced — in a post that read like a direct response to the Meta Muse privacy storm — that it will require much more explicit user action before granting Full Disk Access. ChatGPT for Mac, notably, offers Apple Messages integration that depends on exactly that permission.

Wardle's analogy is the building manager who holds keys to every room: if someone can manipulate the manager, everything entrusted to the building becomes reachable. Desktop assistants are, by design, building managers. They read files, send messages, and act on the user's behalf — which means their process architecture, not just their model behavior, is now part of the attack surface.

OpenAI said it continues to improve its security practices while acknowledging it needs to move faster. Wardle, for his part, is not done: he has submitted another vulnerability report to OpenAI, this one concerning the integration between ChatGPT and the Codex assistant, which the company is reviewing. In November he will present analysis of several bugs in macOS AI apps at the security conference Objective by the Sea. The message to every lab shipping an agent is fairly clear — your app's privilege model will be audited by people who read check-raising code for breakfast, and "insanely trivial" is a grade you do not want to receive.

Comments (0)

Log in to join the discussion

Log In

No comments yet