OpenAI’s Apple Messages plugin can search, summarize, draft, and send iMessage, SMS, and RCS conversations in ChatGPT Work and Codex on Apple silicon Macs. The “spyware” label is a criticism of the permission model and consent problem—not an established finding that OpenAI is secretly surveilling users.
Research answer

Create a landscape editorial hero image for this Studio Global article: What are the capabilities, availability, and required permissions of OpenAI’s Apple Messages plugin for ChatGPT Work and Codex on Apple Sili. Article summary: OpenAI’s Apple Messages plugin gives ChatGPT Work and Codex unusually broad access to a Mac’s Messages data: it can search iMessage, SMS, and RCS conversations, analyze or summarize them, draft replies, and send messages. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts w
OpenAI’s Apple Messages plugin turns the ChatGPT desktop app into an interface for Apple’s Messages app. On compatible Macs, it can search conversations, analyze or summarize threads, draft replies, and send messages through Messages. The feature is available through ChatGPT Work and Codex rather than ordinary ChatGPT chats, and it is not currently a mobile or iPhone integration. 72339
That convenience comes with an unusually consequential permission decision: enabling the feature can give ChatGPT access to a private communications archive that includes messages written by people who never agreed to share them with an AI system.
The plugin works with three message types handled by Apple’s Messages app:
Within ChatGPT Work and Codex, it can read and search those conversations, retrieve information from them, summarize threads, prepare replies, and send messages through Messages. 81939
This is more than a simple copy-and-paste assistant. The plugin can help answer questions about a conversation or identify patterns across an archive, such as who a user talks to and what those discussions concern. That broader analysis is one reason the feature has attracted more scrutiny than an integration limited to drafting a single text. 8
The plugin is designed for the ChatGPT desktop app on macOS and currently works on Apple-silicon Macs. It is available for use in ChatGPT Work and Codex, not in regular ChatGPT conversations, the web interface, or mobile apps. 72023
The plugin directory may be visible across ChatGPT plans, but actual use can depend on the plan, workspace, role, interface, and app permissions. In Business and Enterprise/Edu workspaces, administrators can manage plugin installation and underlying app access; managed-workspace administrators can also disable Apple Messages through the existing Computer Use control. 32383940
It is therefore not an iPhone feature. A user cannot install the plugin on an iPhone and ask ChatGPT to operate Messages there. The relevant exposure is on a Mac where the user’s Messages history is available locally. 720
The most significant requirement is Full Disk Access in macOS System Settings. Reports also describe permissions involving contacts and automation, which allow the app to identify recipients and interact with Messages. 1923
Full Disk Access is not a narrowly scoped “Messages only” entitlement. macOS describes it as access that can expose protected data belonging to other applications. Reporting on this integration has specifically raised the possibility that the permission could reach other local material, including Mail data, Safari data, and backups. 20
That distinction matters. A user may think they are authorizing ChatGPT to read text messages, while the underlying macOS permission represents a much wider trust decision. The plugin’s actual Messages workflow may retrieve only information relevant to a request, but the operating-system permission itself is broader than the feature’s headline purpose.
The word “spyware” is being used as a criticism of the design and risk model, not as an established legal or technical finding that OpenAI is covertly monitoring users. Privacy researcher Paul Walsh argued that combining Full Disk Access with automation permissions lets ChatGPT reach readable copies of iMessage, SMS, and RCS conversations on a Mac. Other critics, including developer Steve Moraco, have raised similar concerns about the possibility that retrieved messages could be sent to model infrastructure. 3031
The criticism rests on three related issues:
Full Disk Access can expose protected information from more than one application. Critics object that an AI assistant capable of searching and acting on communications should not need a permission with such a wide potential reach. 2031
The Mac owner can choose to enable the plugin, but the contents of a message thread usually belong to a conversation between multiple people. Those correspondents may not use ChatGPT, know that the integration is active, or have an equivalent way to withdraw their messages from the workflow.
This creates a third-party-consent problem: the person who grants access controls the device, but not necessarily all of the information stored on it. Reporting has highlighted that the plugin can reach extensive conversation histories, including private and end-to-end encrypted messages that were never written with AI analysis in mind. 2231
OpenAI’s local-processing description addresses how the plugin reaches Messages on the Mac. It does not, by itself, answer what selected content is sent to ChatGPT when the user asks for a summary, search result, or drafted reply, or how that content is handled under every configuration.
That is why “it runs locally” and “there is no server-side Messages archive” do not completely resolve the privacy debate. They may limit exposure compared with continuously uploading an entire message database, but they do not mean that no message content can leave the device during an AI request.
The reported safeguards are meaningful, but each addresses a different part of the risk.
These controls reduce some risks, especially accidental sending. They do not eliminate the underlying question of whether a device owner should be able to expose a shared conversation archive to an AI assistant without the other participants’ knowledge.
The comparison is useful only if its limits are clear.
The concern in both cases involves information about people who may not have directly signed up for or consented to a service. With the Apple Messages plugin, however, the immediate issue is access to other people’s messages through a ChatGPT user’s Mac—not evidence that OpenAI is building a persistent Facebook-style profile of every nonuser mentioned in those conversations.
A better description is indirect exposure: one person’s decision can make a shared archive searchable, summarizable, and usable for drafting messages. That is a serious consent and privacy concern, but it is not the same mechanism as a platform compiling a separate profile of nonusers.
The plugin puts pressure on Apple’s privacy brand because a third-party AI can operate on Messages content when a Mac owner grants the necessary permissions. That reputational issue is separate from Apple’s lawsuit against OpenAI. 15
Apple’s lawsuit concerns alleged trade-secret misappropriation connected to OpenAI’s consumer-hardware ambitions. OpenAI has asked for the case to be dismissed and says it does not have, and does not want, Apple’s trade secrets. The reported lawsuit is not a case about the Apple Messages plugin or a direct challenge to iMessage’s encryption model. 416
The timing nevertheless makes the integration more politically and commercially awkward. Apple presents privacy as a core product value, while the plugin demonstrates how a user-authorized third-party application can gain access to data that Apple’s own systems protect from direct access by outsiders.
The Apple Messages plugin is not hidden spyware in the ordinary sense: it is an opt-in feature with visible permissions, default approval before sending, and workspace-level controls. But the “spyware” criticism identifies a real design tension.
The feature combines an AI system, a broad macOS permission, and a long-lived communications archive containing other people’s words. Before enabling it, Mac users should understand that they are not only granting access to their own messages. They may also be making conversations involving friends, family, colleagues, and group members available to an AI workflow—without those people receiving a separate permission prompt.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
OpenAI’s Apple Messages plugin can search, summarize, draft, and send iMessage, SMS, and RCS conversations in ChatGPT Work and Codex on Apple silicon Macs.
OpenAI’s Apple Messages plugin can search, summarize, draft, and send iMessage, SMS, and RCS conversations in ChatGPT Work and Codex on Apple silicon Macs. The “spyware” label is a criticism of the permission model and consent problem—not an established finding that OpenAI is secretly surveilling users.