MediumNewsLLM-specific
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
- Published
- Record updated
Summary
Researchers at the Objective-See Foundation found a flaw in the macOS version of OpenAI's ChatGPT app that could let an attacker take over the app on a victim's computer. The bug let unprivileged code pass signature checks by routing a request through a trusted script interpreter, exposing chat logs, stored data and browser sessions. OpenAI acknowledged the flaw and fix in its system change log on September 25.
Mitigation
OpenAI patched the flaw, as acknowledged in its system change log on September 25. The source does not give a fixed version number or further mitigation steps.
Related items
- InfoOpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSame vendor · SecurityWeek
- Info‘Pure insanity’: Mathematicians will need years to make sense of OpenAI’s latest dropSame vendor · The Verge (AI)
- InfoOpenAI reports three new incidents of misalignmentSame vendor · CSO Online
- InfoOpenAI's revenue scare, Delta earnings, what investors think of a Starbucks-Chipotle deal and more in Morning SquawkSame vendor · CNBC Technology
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology