ChatGPT macOS Vulnerability Let Malware Borrow Trust
A Flaw in the ChatGPT Mac App
A vulnerability in the ChatGPT app for macOS let an ordinary program on the computer run commands through a trusted OpenAI process. Security researcher Patrick Wardle needed only about 12 lines of code to bypass the protection.
The flaw is tracked as CVE-2026-100754. OpenAI fixed the bug on September 25, 2026, in ChatGPT version 26.924.20706. No signs of real-world attacks have been found so far.
How ChatGPT Checked Trust
ChatGPT checked the digital signatures of processes. In this way, it told its own components apart from outside programs.
The check covered more than the process that contacted the app. It also covered that process’s parent and the level above it in the chain.
How Wardle Broke the Chain
Wardle discovered a weak spot inside ChatGPT itself. A trusted script interpreter could accept commands from outside code.
The researcher launched that interpreter three times. As a result, he built a chain of processes that ChatGPT considered legitimate. Foreign commands then ran inside the app’s trusted process.
Why the Risk Matters
Through this mechanism, malware could potentially reach ChatGPT’s data. It could also use permissions the user had already granted to the app.
The danger is especially clear for AI clients. Users often give them access to files, the browser, and other apps.
The Limits of the Flaw
However, the bug did not allow a remote hack of any Mac with ChatGPT installed. An attacker first had to run unprivileged code on the victim’s computer. Only after that could CVE-2026-100754 help cross the trust boundary and act through ChatGPT.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.