漏洞允許已在同一台 Mac 執行的程式,利用可信任的指令碼直譯器繞過 ChatGPT 內部檢查,可能讀取已儲存的對話及應用程式可存取的連結資料;攻擊程式不必先取得較高權限。
這是應用程式內的信任邊界問題,不代表可遠端發動攻擊,也不等於能不受限制地控制整台 Mac。
What was the vulnerability in OpenAI’s ChatGPT app for macOS that Objective-See researchers discovered, how could an attacker use a trustedIllustration of the security risks that can arise when an app trusts a signed component to carry commands.
AI 提示詞
Create a landscape editorial hero image for this Studio Global article: What was the vulnerability in OpenAI’s ChatGPT app for macOS that Objective-See researchers discovered, how could an attacker use a trusted. Article summary: Objective-See researchers found a local trust-boundary flaw in ChatGPT for macOS: the app could accept commands from an attacker-controlled script as though they came from a trusted component. An exploit could potentiall. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts wi
openai.com
Objective-See Foundation 研究人員發現,macOS 版 ChatGPT 曾有一項本機安全漏洞:攻擊者可利用可信任的指令碼直譯器,讓未受信任的指令看起來像是來自 ChatGPT 的可信元件。若攻擊成功,可能接管 ChatGPT 應用程式,並存取該應用程式能讀取或使用的資料。247
漏洞如何繞過信任檢查?
ChatGPT for macOS 會透過程序與程式碼簽章檢查,判斷應用程式各元件是否可信。問題在於,攻擊者可以借用一個受信任的指令碼直譯器,把未受信任的指令碼送進 ChatGPT 主程式;檢查機制認出了直譯器,卻沒有充分確認它所承載的指令碼及指令是否可信。45
這不是單靠網路就能發動的遠端攻擊:攻擊者必須先讓惡意程式在受害者的 Mac 上執行。不過,相關報導指出,執行該程式不需要管理員或 root 等較高權限。78