A recently patched vulnerability in OpenAI’s version of ChatGPT for macOS shows how valuable it is for attackers to crack the AI software itself. Especially as such applications become more widespread.

Source image: Unsplash, Maria Shalabaieva
This vulnerability can be used to effectively control ChatGPT on the victim’s computer. In this case, the attacker could access all chat history and other data stored in the application, as well as related resources such as browser sessions. The vulnerability, discovered by researchers at the Objective-See Foundation, illustrates the deep system access and high level of trust required by artificial intelligence platforms to perform their functions. The case also shows how such platforms can therefore become attractive targets.
“These agents need broad access to perform their tasks. They are like building managers who have the keys to all the rooms. So if their jobs could be compromised or taken over, it could create serious problems. This could mean that low-privileged code could gain access to all protected resources.”“,” Patrick Wardle, a software analyst at the Objective-See Foundation and a longtime macOS security researcher, told Wired.
Open Artificial Intelligence Company publicly acknowledged The vulnerability exists and was fixed in the system change log on September 25. “We continue to improve our safety practices but recognize the need to act more quickly.”“OpenAI representative Shane Bauer told Wired.
The ChatGPT application for macOS consists of many components that communicate with each other over a secure channel to verify digital signatures. The purpose of these checks is to confirm that both communicating processes are OpenAI components and not third-party software and possible malware making the request. This system architecture provides the ability to check signatures at three nested levels relative to the request itself. This ensures that malware cannot somehow trick the OpenAI component into acting as an intermediary and making seemingly trustworthy requests.
Researchers from the Objective-See Foundation discovered the existence of a trusted component (a script interpreter) that accepts untrusted scripts (a list of commands to be executed). This element can be manipulated to inject such a script into the main ChatGPT process. “The system also checks for parent and grandparent processes, but the malicious script simply runs the interpreter three times and then sends the request, thus satisfying all verification requirements.””, Waddell explained.
Image source: Unsplash, Flipsnack
According to him, the purpose of exploiting the vulnerability is to “ridiculously simple”it only took about a dozen lines of code to create a prototype that demonstrated the problem. In addition to accessing chat history in ChatGPT, the vulnerability could force the chatbot to execute the attacker’s commands, such as launching a browser or accessing other critical applications. At the same time, these requests look like legitimate instructions from the OpenAI software itself.
In November, at the Objective by the Sea conference dedicated to Apple ecosystem security, Wardle will present the results of using artificial intelligence technology to analyze multiple vulnerabilities in macOS applications. He recently discovered and reported a fix for a vulnerability in the dictation function of Meta’s new artificial intelligence assistant, Muse.✴. A local attacker (with direct access to the victim’s device) could use this to intercept mishandled authentication tokens and gain access to user data. Wardle also said that he has provided OpenAI with information about new vulnerabilities related to the integration of ChatGPT and the new Dots AI assistant, which is constantly running in the background. OpenAI is currently working on his report.
“Artificial intelligence companies are now obsessed with introducing new features. But, as always, the more features, the wider the attack surface. Therefore, all these companies need to prioritize security, but it seems that this aspect is often ignored.”Wardle pointed out.
If you find an error, select it with your mouse and press CTRL+ENTER.
