What was the vulnerability in OpenAI’s ChatGPT app for macOS that Objective-See researchers discovered, how could an attacker use a trustedIllustration of the security risks that can arise when an app trusts a signed component to carry commands.
AI 提示
Create a landscape editorial hero image for this Studio Global article: What was the vulnerability in OpenAI’s ChatGPT app for macOS that Objective-See researchers discovered, how could an attacker use a trusted. Article summary: Objective-See researchers found a local trust-boundary flaw in ChatGPT for macOS: the app could accept commands from an attacker-controlled script as though they came from a trusted component. An exploit could potentiall. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts wi
openai.com
Objective-See Foundation 的研究人员发现,ChatGPT macOS 应用曾有一处信任边界漏洞:应用可能把由不可信脚本传入的命令,当成来自可信组件的请求。若攻击者利用这一缺陷,可能接管 ChatGPT 应用,并访问应用本身能够读取或调用的数据与服务。247
漏洞如何绕过应用检查
ChatGPT for Mac 会检查进程及代码签名,以区分可信组件和不受信任的代码。问题在于,攻击者可以借助一个受信任的脚本解释器,把不可信脚本传入应用。换句话说,应用认出了“解释器”是可信的,却没有充分确认解释器带来的脚本和命令是否可信。45
利用这一漏洞需要先让恶意代码在受害者的 Mac 上运行,因此它并非仅凭远程连接就能发动的攻击。不过,据报道,所需代码不必拥有管理员或 root 权限。78