
A vulnerability could turn the ChatGPT app on a Mac into a tool for other software. A current heise report published on October 5 describes the flaw found by Patrick Wardle and the Objective-See Foundation, which OpenAI has already fixed. The practical implication is straightforward: What matters is the installed desktop app release, rather than the model selected in the chat.
Key takeaways
- OpenAI documents the fix for CVE-2026-100754 in its September 25 macOS security update and names version 26.924.20706.
- The described attack required malicious code to be running on the affected Mac already.
- A trusted app component could pass along outside instructions. App data and other authorized access were therefore potentially reachable.
- The reports do not establish successful exploitation against specific users. Potential harm needs to be distinguished from demonstrated data theft.
- App updates and macOS permissions serve different purposes. Changing the model does not fix this software flaw.
The fix predates the current report
The headline might leave readers assuming the flaw is still open. However, the sequence matters: OpenAI lists the correction under September 25 in its combined ChatGPT and Codex changelog. The entry explicitly names CVE-2026-100754 and fixed version 26.924.20706, and thanks Patrick Wardle of the Objective-See Foundation. The October 5 heise report explains a case that has already been addressed.
A CVE identifier provides a reference for a specific vulnerability. On its own, it does not tell us how many people were affected or whether an attacker actually exploited the flaw. The report’s publication date is also different from the date the corrected software became available. Keeping these dates separate prevents a later technical explanation from turning into a claim of a new, ongoing wave of attacks.
The short manufacturer notice confirms the fix but does not provide a complete technical analysis. Additional details come from reporting and Wardle’s explanations. For readers, this means the corrected flaw is documented, while the specific attack path is explained through the research described. That does not support a comprehensive claim about every possible consequence on every Mac.
When a trusted component carries outside commands
Desktop apps often consist of several cooperating processes. Digital signatures help them check who is making a request. In the reported case, however, a script interpreter belonging to the app could accept outside instructions and pass them into processing considered trusted. A script interpreter is software that executes a list of commands. The weakness was therefore in checking a request’s origin, rather than in a persuasive response from the language model.
WIRED identifies previously installed malware as a prerequisite. Heise reports potential access to conversation history and further access within the app’s permissions. This is a local attack path: Other software on the computer attempts to take advantage of the app’s trusted position. The report does not describe unrestricted remote access simply because someone installs ChatGPT or enters an ordinary message.
This distinction remains relevant after the fix. Correcting an app vulnerability does not automatically remove malware that might already be present on a computer. Conversely, having installed an earlier app release does not establish that a compromise occurred. Without further evidence, sweeping claims about stolen chats or completely compromised Macs would be unjustified.
The case adds to the discussion of Apple’s announced changes to Full Disk Access. That issue concerns deliberately granting broad permissions. This case concerns whether outside software can appear authorized within an application. The two are connected, but they are different problems requiring different measures.
What matters on your own Mac
The desktop app should first be running a current software release. OpenAI’s documentation explains that the app normally checks for updates and installs them automatically. Managed organizations can disable this internal updater; they then need to distribute new releases through device management. A working chat is therefore not reliable proof that the local software has already been corrected.
On a personal computer, a useful check is whether an offered app update has finished completely. On a work device, IT administrators can help confirm the release actually installed. People using similar chat interfaces in several apps should also identify the affected desktop application clearly. Switching the AI model in a selection menu does not update local program components.
Existing file and folder permissions can be reviewed separately. Apple’s instructions for current System Settings point to Privacy & Security, followed by Files & Folders. Access listed there can be changed for individual apps. The decision should reflect actual use: Someone explicitly handing over a document does not necessarily need to grant ongoing access to an entire folder.
Apple treats access to the entire internal storage device, accessibility, and automation as separate permission categories. Access to one folder should therefore not be equated with every other permission. Before removing a permission that may be needed, users should understand which feature uses it. Reviewing permissions can reduce unnecessary reach; it does not replace the app update that addresses this particular flaw.
A better standard for desktop assistants
The strength of local assistants is their ability to work with real materials. This corrected case highlights the technical requirement behind that capability: Every component needs to identify not only its communication partner, but also reliably check authorization for the task being passed along. For vendors, that is a concrete engineering requirement. For users, a good assistant is one whose software release can be verified and whose access matches the actual task. A longer list of available features does not answer those questions on its own.
Sources
- OpenAI: macOS security update 26.924, 25. September 2026
- heise / Mac & i: ChatGPT-App für macOS war angreifbar, 5. Oktober 2026
- WIRED: ChatGPT Mac app vulnerability, Interview mit Patrick Wardle
- OpenAI: Manage app updates
- Apple: Control access to files and folders on Mac
- Apple Platform Security: Controlling app access to files in macOS

