Saw it on WIRED: A macOS client for ChatGPT has just patched a vulnerability—an Objective-See researcher found that malicious scripts can bypass signature verification between components, effectively taking over the local ChatGPT instance. Chat history and browser sessions can all be accessed.
On September 25, OpenAI admitted it in the changelog and issued a patch. The prerequisite is that the machine already has malware installed; the researcher says a PoC takes roughly a dozen lines. The same team previously fixed a token issue in Meta Muse transcription, and now they’re investigating a new vulnerability for Dots.
As AI clients gain more privileges, they’re becoming targets themselves—features stack up too fast, while security often can’t keep up.
#AI #OpenAI #ChatGPT #Security
On September 25, OpenAI admitted it in the changelog and issued a patch. The prerequisite is that the machine already has malware installed; the researcher says a PoC takes roughly a dozen lines. The same team previously fixed a token issue in Meta Muse transcription, and now they’re investigating a new vulnerability for Dots.
As AI clients gain more privileges, they’re becoming targets themselves—features stack up too fast, while security often can’t keep up.
#AI #OpenAI #ChatGPT #Security
