A vulnerability in the macOS version of OpenAI's ChatGPT has been patched, highlighting the risks associated with AI software. The flaw could have allowed attackers to take control of ChatGPT on a user's computer, accessing chat logs and other stored data, as well as browser sessions. Researchers from the Objective-See Foundation discovered the vulnerability, which underscores the level of system access that AI platforms require and the associated security risks.
Patrick Wardle, a software analyst at Objective-See Foundation, explained that AI agents require extensive access to function effectively, akin to a building manager with keys to all rooms. If compromised, this access could allow unprivileged code to gain extensive control. OpenAI acknowledged the security flaw and its fix in a change log on September 25, with spokesperson Shane Bauer stating that the company is evolving its security practices.
The ChatGPT macOS app uses multiple components that communicate securely through digital signature checks to verify the legitimacy of requests. However, researchers found that a trusted component could accept untrusted scripts, which could be manipulated to execute commands within the main ChatGPT process. Wardle noted that exploiting this vulnerability was relatively simple, requiring only a dozen lines of code. This flaw could enable attackers to access ChatGPT chat logs and execute commands that appear to be legitimate.
Wardle plans to present his findings on AI macOS application vulnerabilities at the Objective by the Sea security conference in November. He has also identified a flaw in Meta's Muse AI assistant and submitted a new vulnerability report to OpenAI regarding its integration with the Dots AI assistant, which is currently under review. Wardle emphasized the need for AI companies to prioritize security as they add features, warning that an expanded feature set increases the attack surface.