ChatGPT Mac App Flaw Exposed User Data to Hackers
A recently discovered security vulnerability in OpenAI's ChatGPT desktop application for macOS could have allowed malicious actors to access sensitive user data, including chat history.

A critical security flaw in OpenAI's official ChatGPT desktop application for macOS, discovered by security researcher Doug Billard, could have exposed user data to unauthorized access. The vulnerability, present in versions released between December 2023 and April 2024, allowed for the retrieval of sensitive information, including chat conversations, in plain text if a malicious script was executed on a user's Mac. While OpenAI has since addressed the issue, the discovery highlights ongoing security challenges with desktop applications that handle personal data.
The vulnerability stemmed from how the macOS version of ChatGPT handled local data storage. According to Billard's findings, the application stored chat logs and other sensitive user information in an unsecured SQLite database file located within the user's Library directory. A specially crafted web page or application could, under certain circumstances, trick the ChatGPT app into revealing the contents of this database. This would mean that a hacker, or even a malicious website, could potentially gain access to a user's entire chat history without explicit permission.
How the Flaw Could Be Exploited
Exploiting the flaw required a specific sequence of events. A user would first need to have the ChatGPT desktop app installed and have interacted with it, generating stored chat data. Then, the user would need to visit a malicious website or open a compromised application. This malicious entity would then attempt to trigger the vulnerability, potentially using a method similar to a cross-site scripting (XSS) attack tailored for the desktop application's environment. If successful, the attacker could access the unencrypted chat data. Billard demonstrated that this could be achieved with a relatively small amount of code, making it a plausible threat vector.
OpenAI confirmed the vulnerability and stated that it was fixed in updates released on April 24, 2024. The company noted that the flaw did not affect other ChatGPT applications or the web version. "We have released an update to address this issue," an OpenAI spokesperson said. "We are grateful to the security researcher who brought this to our attention." The company did not provide details on whether the vulnerability was actively exploited in the wild before its discovery.
This incident underscores the security considerations inherent in developing and deploying desktop applications, especially those that handle large amounts of user data. Unlike web applications, which often operate within the more controlled environment of a browser sandbox, native desktop applications can have broader access to a user's system. Developers must implement robust security measures to protect local data storage and prevent unauthorized access, including proper encryption and strict input validation to guard against malicious scripts.
The use of SQLite databases for storing sensitive information is common, but proper security protocols are crucial. This includes ensuring that such databases are encrypted, access is strictly controlled, and any data transmitted or accessed is done so over secure channels. For users, it serves as a reminder to keep all software, including desktop applications, updated to the latest versions, as patches often contain critical security fixes. Additionally, practicing good general cybersecurity hygiene, such as being cautious about the websites visited and links clicked, remains a vital defense.
