OpenAI 列明漏洞 CVE 2026 100754 已在 macOS 版本 26.924.20706 修補,並感謝 Objective See Foundation 的 Patrick Wardle。[1]
How did the Objective-See Foundation researchers discover and exploit the flaw in OpenAI’s ChatGPT macOS app, what access and permissions diA local software flaw can put an app’s stored data and connected services at risk.
AI 提示
Create a landscape editorial hero image for this Studio Global article: How did the Objective-See Foundation researchers discover and exploit the flaw in OpenAI’s ChatGPT macOS app, what access and permissions di. Article summary: Objective-See researchers found that ChatGPT’s Mac app could mistake attacker-supplied instructions for commands from a trusted component. The attack required code already running on the victim’s Mac, but not privileged . Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
openai.com
ChatGPT macOS 版曾有一個漏洞,可能讓已在目標 Mac 執行的惡意程式,透過應用程式冒充可信元件。Objective-See Foundation 研究人員指出,潛在影響包括讀取已儲存的對話,以及觸及瀏覽器工作階段等連接功能。OpenAI 的更新紀錄列明,漏洞 CVE-2026-100754 已在 macOS 版本 26.924.20706 修補。13
漏洞是怎樣運作?
ChatGPT Mac 版由多個元件組成,元件之間會檢查請求是否來自軟件內可信部分。研究人員發現,攻擊者可以借助一個受信任的指令碼解譯器,把未受信任的指令傳入 ChatGPT 主程序,繞過相關檢查。69