In short: The Objective-See Foundation found a flaw in the ChatGPT app for macOS tracked as CVE-2026-100754: malicious code already running on a victim's Mac without elevated privileges could trigger a built-in script interpreter three times in a row and trick the main app process into treating its commands as coming from a trusted OpenAI component. From there, an attacker could access the entire chat history, app data, and linked browser sessions — and it turned out the chats themselves were stored as plain, unencrypted text on disk. OpenAI confirmed the issue and patched it on September 25, 2026, in app version 26.924.20706; no confirmed real-world exploitation has been reported.
What researchers actually found
Multiple outlets, including ForkLog, reported that ChatGPT for Mac stored every conversation in plain, unencrypted text on disk — a risk on its own, since any program with file-system access could read it. Researcher Patrick Wardle and the Objective-See Foundation went further and found a way to bypass the trust verification between app components: a built-in script interpreter, nominally "trusted," could be abused to relay commands as if they came from a legitimate OpenAI process.
How the attack worked
The attack required malicious code to already be executing on the victim's Mac, even without admin rights (for example, via a previously installed infostealer or trojan). That code could sequentially trigger ChatGPT's built-in script interpreter three times — after the third call, the main app process could no longer distinguish the attacker's request from a genuine trusted OpenAI component. From there, an attacker could effectively control the app on someone else's computer: reading the full chat history, integration data, and linked browser sessions.
What this means for ordinary users
The takeaway isn't that "ChatGPT is unsafe" — it's that desktop AI apps have become a new target for malware, right alongside browsers and email clients. People discuss passwords, work documents, personal problems and financial details in chats with a bot, often without thinking about the fact that this data sits on disk in plain text. We've covered what AI tools actually collect and how to limit their reach separately: VPN and neural networks: protecting your data in ChatGPT and Claude.
What you can do now
- Update ChatGPT for macOS to version 26.924.20706 or later — the patch closes the gap and encrypts the local chat store.
- Don't run untrusted files or extensions. The attack needs malware already present on the machine — basic hygiene (antivirus, caution with attachments and pirated software) removes the precondition entirely.
- Don't paste passwords, access codes, or financial details into AI chats — treat your chat history as a sensitive asset, just like email or notes.
- Encrypt your network traffic. A local app vulnerability isn't something a VPN protects against, but LiMP VPN covers an adjacent risk: traffic interception on public networks and ISP visibility into which services you use.
Plans with a verified no-logs policy: LiMP VPN pricing. More breakdowns of privacy incidents and data leaks on the LiMP VPN blog.
