ChatGPT for Mac 曾有漏洞,讓已在同一部 Mac 執行的程式借助可信任的指令碼解譯器繞過內部檢查,可能讀取已儲存的對話,或透過 ChatGPT 存取連接服務的資料。 這屬於本機攻擊,程式毋須管理員權限;資料存取範圍取決於 ChatGPT 本身可用的資料及權限,並不代表攻擊者可全面控制整部 Mac。
What was the vulnerability in OpenAI’s ChatGPT app for macOS that Objective-See researchers discovered, how could an attacker use a trustedIllustration of the security risks that can arise when an app trusts a signed component to carry commands.
AI 提示
Create a landscape editorial hero image for this Studio Global article: What was the vulnerability in OpenAI’s ChatGPT app for macOS that Objective-See researchers discovered, how could an attacker use a trusted. Article summary: Objective-See researchers found a local trust-boundary flaw in ChatGPT for macOS: the app could accept commands from an attacker-controlled script as though they came from a trusted component. An exploit could potentiall. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts wi
openai.com
Objective-See Foundation 研究人員發現,ChatGPT for macOS 曾有一個信任檢查漏洞:攻擊者可利用可信任的指令碼解譯器,把不可信任的指令碼送入 ChatGPT,令程式錯把惡意指令當成來自可信元件。若攻擊成功,可能接管 ChatGPT 應用程式,並接觸應用程式本身可使用的資料。 247
不過,這並非隔空就能發動的攻擊。惡意程式必須先在受害者的 Mac 上執行,而且報道指不需要管理員或 root 權限。 78
ChatGPT for Mac 曾有漏洞,讓已在同一部 Mac 執行的程式借助可信任的指令碼解譯器繞過內部檢查,可能讀取已儲存的對話,或透過 ChatGPT 存取連接服務的資料。
首先要驗證的關鍵點是什麼?
ChatGPT for Mac 曾有漏洞,讓已在同一部 Mac 執行的程式借助可信任的指令碼解譯器繞過內部檢查,可能讀取已儲存的對話,或透過 ChatGPT 存取連接服務的資料。 這屬於本機攻擊,程式毋須管理員權限;資料存取範圍取決於 ChatGPT 本身可用的資料及權限,並不代表攻擊者可全面控制整部 Mac。