A flaw in ChatGPT’s Mac app that could expose private chats was found and patched
Patrick Wardle of the Objective-See Foundation found a flaw in ChatGPT’s Mac app, tracked as CVE-2026-100754. The app used signature checks to confirm requests came from trusted OpenAI components, but a script interpreter inside that trusted chain could run outside code. Unprivileged code already running on a Mac could abuse it to reach chat history, data stored by the app and connected browser sessions. Wardle called the bug “insanely trivial” to exploit. OpenAI fixed it on September 25 in version 26.924.20706, and no real-world exploitation has been reported.
Sources
- WIRED, “A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data”, (wired.com)
- OpenAI, “ChatGPT & Codex changelog”, (learn.chatgpt.com)
- Feedly (CVE kaydı), CVE-2026-100754 record summary, (feedly.com)
About this story
This story was posted on Instagram by @jarrus.tech on Oct. 10, 2026.
Spotted an error in this story? [email protected] · Instagram
Short link: thejarrus.com/en/chatgpt-mac-flaw
This story in Turkish: ChatGPT’nin Mac uygulamasında özel sohbetleri açığa çıkarabilecek bir güvenlik açığı bulundu ve kapatıldı
On the same topic
Robot tests: even the best model completed only 19% of 84 robot tasks, and 63 tasks were solved by no model
In RobotWorld, a benchmark released October 7, the top model, GPT-6 Astra, completed only 16 of 84 simulated robot tasks; no model solved 63 of the tasks.
OpenAI’s image model posts a near-perfect score on text-dense images
On UltraText Bench, a dense-text test led by Westlake University, OpenAI’s GPT Image 2 ranked first of 24 configurations with 99.35 out of 100.
AWS adds Chinese lab Z.ai’s GLM 5.3 model to Amazon Bedrock
AWS added GLM 5.3, a 753-billion-parameter model from Beijing-based Z.ai (formerly Zhipu AI), to Amazon Bedrock for eligible enterprise customers on October 5.