Researchers at the Objective-See Foundation found a now-patched vulnerability in the macOS ChatGPT app that could have let an attacker take over the app on a victim's machine, exposing chat logs and linked data such as browser sessions. OpenAI confirmed the flaw and fix in a September 25 system change log entry and said it is working to speed up its security practices.
wired.com
· 2026-10-02
Security researcher Patrick Wardle found an unpatched setting in Meta's Muse macOS app that let local attackers reroute the app's cloud-based dictation to their own server, effectively seizing control of the AI agent. Wardle demonstrated the flaw by using Muse's own privileges to snap photos and write files to disk, often without alerting the user. Meta issued a hotfix within hours of the report, though it maintains the exploit required existing local access and posed low real-world risk.
theverge.com
· 2026-09-22