A flaw in the ChatGPT app for macOS could have let malicious code already running on a Mac act through the app as though it were a trusted component. Researchers at Objective-See Foundation reported that the potential reach included stored chats and connections such as browser sessions. OpenAI’s changelog lists the fix as CVE-2026-100754 in macOS version 26.924.20706.
1
3
How the exploit worked
ChatGPT’s Mac app uses components that check whether requests come from trusted parts of the software. Researchers found that a trusted script interpreter could be used to pass untrusted instructions into the main ChatGPT process, bypassing those checks.
6
9
The available reporting describes the technical path, but does not establish what first prompted the researchers to investigate it. Some coverage characterizes the proof of concept as only about a dozen lines of code; that describes the reported demonstration, not a requirement that every attack use the same code.
2
What access did an attacker need?
This was a local attack: malicious code had to be running on the target Mac. Objective-See described the attacker as unprivileged, and reporting likewise says elevated privileges were not required. The evidence does not support describing this as a remote attack that could take over the app simply through a ChatGPT message.
9
16
What could the attacker potentially reach?
If exploited, the flaw could let an attacker take control of the ChatGPT app’s process, read chats and other data stored by the app, and issue commands through it. Reporting also identified connections such as browser sessions as possible targets. The impact on connected services would depend on the integrations and access available on that user’s Mac.
3
7
These are potential consequences of the flaw, not evidence that attackers used it against users. The available sources do not establish real-world exploitation.
OpenAI’s fix
OpenAI’s changelog says CVE-2026-100754 was fixed in macOS version 26.924.20706 and credits Patrick Wardle of Objective-See Foundation.
1 A separate update listing dates the security update to September 25, 2026; the changelog excerpt confirms the version and fix but does not itself state that date.
28
Mac users should check that they have a version containing the fix. The listed version is the one OpenAI identifies for this security update.
1
How this differs from an earlier ChatGPT Mac security issue
In 2024, a separate issue drew attention to ChatGPT conversations stored locally in plain text. Coverage at the time reported that OpenAI updated the app to encrypt locally stored records.
21
23 That incident concerned how chats were stored; the later Objective-See finding concerned how untrusted code could pass as a trusted component. The supplied sources do not establish that the two flaws shared a technical cause.
1
21
The broader lesson: an assistant’s access shapes the risk
The practical concern is not only whether an AI assistant has a vulnerability. It is also what the assistant can reach if its process is compromised. Chats, app data, and connected services can raise the consequences of a security failure.
3
26
OpenAI’s patch addresses this particular vulnerability, but it does not resolve the broader design trade-off: system access can make an assistant more useful while increasing what an attacker might reach if the assistant is subverted. The evidence here supports that general caution; it does not establish the details of other related findings by Wardle or prove that the earlier storage issue led to this flaw.