Safety#Security scan#AI safety

A ChatGPT Mac app flaw allowed process injection; OpenAI patched it September 25

Objective-See disclosed a ChatGPT macOS flaw: a trusted interpreter ran untrusted scripts and three spawns beat signature checks; OpenAI fixed it September 25.

An open combination lock resting on a laptop keyboard

Patrick Wardle of the Objective-See Foundation disclosed a high-severity flaw in the ChatGPT macOS app: with malware already resident, an attacker could inject code into the ChatGPT main process and read sensitive data. OpenAI shipped the fix on September 25.

The facts

  • The mechanism: the ChatGPT app bundles a trusted script interpreter that executes untrusted scripts; spawning it three times satisfied macOS’s parent/grandparent signature checks (the TCC attribution logic), letting injected code into the main process.
  • Impact: access to chat logs and stored app data, browser sessions, and the ability to fake legitimate OpenAI requests.
  • The cost: Wardle calls it “insanely trivial” — about a dozen lines of code, requiring malware already on the machine.
  • Fix and response: OpenAI patched it September 25 (visible in the changelog); spokesperson Shane Bauer acknowledged “a need to move faster.”
  • What is next: no in-the-wild exploitation, no CVE; Wardle presents more AI-app macOS bugs at Objective by the Sea in November, with a new ChatGPT/Dots finding under review.

A new attack surface

The generic AI-app shape — main process plus helpers plus a bundled interpreter plus broad file access — is the inverse of macOS’s defense-in-depth assumptions. Traditional apps rarely assemble their own trusted interpreter; AI apps almost all do, to run prompts and tool calls. Apple tightening Full Disk Access the same week is the system-layer answer; the app-layer answer is code signing and process boundaries redesigned.

A checklist for developers

Three things: audit every bundled interpreter for untrusted-input execution; test your own process tree against “three spawns” attribution bypasses; and put inter-process trust in the threat model — AI apps run much deeper trees than traditional ones.

Editorial take

Wardle’s cadence (find, responsible disclosure, fix, then the conference deep-dive) is how this should work; OpenAI’s “need to move faster” reads sincerely, though how long the flaw predates the fix is undisclosed. AI-app vulnerability disclosure is just starting — November’s conference is the one to watch.

The disclosure timeline, reconstructed

Wardle’s writeup implies the flaw existed from the app’s early builds; the fix shipped September 25 and the disclosure followed within a week — a reasonably tight cycle by industry standards. The unstated question is how long the interpreter-executes-untrusted-scripts pattern predates the fix, and whether other OpenAI desktop surfaces (the Dots agent’s apps) share the code path. Wardle’s November talk will likely answer the second question.

The update-cadence problem

Desktop AI apps ship weekly, and each ship can add a new helper, interpreter or entitlement. The ChatGPT flaw is the first public proof that this cadence outpaces security review — OpenAI’s own spokesperson conceded “a need to move faster.” The industry-standard answer is a bug bounty scaled to desktop surface area; OpenAI’s program exists but this flaw came from an external researcher’s own initiative.

The concrete ask for every AI desktop vendor: publish a desktop security changelog, run a desktop-scoped bounty, and ship helper-process least-privilege by default. The ChatGPT fix note lives in an app changelog that few users read; security-relevant fixes deserve their own channel, the way browsers handle CVEs. Between the fix note and the November talk, expect the plugin ecosystem to get its first audit wave.

The fix note also confirms OpenAI ships a bundled script interpreter at all — an architecture worth questioning in public, not just patching in private.

The technical detail worth stealing for any code review: trust attribution followed process ancestry, so the attack worked by building a chain of legit-looking ancestors rather than breaking any signature. Defenses that check “is this signed” once at launch are structurally blind to it; defenses must re-verify at every privilege boundary. The TCC bypass family has a name now in attacker circles; expect copies within weeks.