OpenAI Fixes Unencrypted Chat Flaw in ChatGPT for macOS

Published:

A security flaw in OpenAI’s new ChatGPT app for macOS raised privacy concerns. Launched last week, the app stored conversations with the AI in plain text on user devices, accessible to anyone with access, including malware.

Security researcher Pedro José Pereira Vieito exposed the vulnerability, demonstrating how another app could read these chats. Vieito even showed how easy it was to create an app that could access these conversations with a click.

The Verge informed OpenAI, who quickly released a fix that encrypts previously unencrypted chats. An OpenAI spokesperson confirmed their commitment to both user experience and security.

Vieito’s investigation stemmed from his curiosity about OpenAI bypassing Apple’s app sandbox protections, which restrict apps’ access to specific areas. Bypassing these restrictions gives the app more freedom, but also creates an oversight gap.

OpenAI may review chats for safety and model improvement (with user consent), but the lack of sandboxing allows other programs, potentially malicious ones, to access these conversations. This vulnerability highlights the importance of secure data storage for user privacy.

Related articles

spot_img