OpenAI’s ChatGPT macOS app had a critical security flaw that could have allowed attackers to access sensitive data, according to researchers. The vulnerability, discovered by the Objective-See Foundation, highlights the risks of compromising AI software as it becomes more prevalent.
The flaw allowed attackers to take over ChatGPT on a victim’s computer, gaining access to all chat logs and other stored data, as well as browser sessions.
"Agents need a lot of access to do their job," said Patrick Wardle, a software analyst at the Objective-See Foundation. "They are like the building manager who has access to the keys to all the rooms.
So if they can be corrupted or subverted, that’s super problematic. It can mean that unprivileged code could then potentially have access to all the things."
OpenAI acknowledged the security flaw and its fix in its system change log on September 25. "We continue to evolve our security practices, but recognize a need to move faster," said Shane Bauer, an OpenAI spokesperson.
The ChatGPT macOS app includes multiple components that communicate securely by checking for digital signatures, but researchers found a trusted component that could be manipulated to deliver malicious scripts into the main ChatGPT process.
"The vulnerability was ‘insanely trivial’ to exploit," Wardle added. "My proof of concept only required about a dozen lines of code." The flaw could have been used to access chat logs or run commands for the attacker, such as accessing a browser or other sensitive applications, with requests appearing as legitimate instructions issued by the OpenAI software.
Wardle will present analysis of several AI macOS application bugs at Objective by the Sea, an Apple-focused security conference in November.
He recently found a flaw in Meta’s Muse AI assistant that could have allowed a local attacker to gain access to user data.
OpenAI is currently reviewing his report about a new vulnerability related to the integration between ChatGPT and its new always-on Dots AI assistant.
"AI companies are fixated on adding features right now," Wardle said. "But as always, the more features, the broader the attack surface. So all of these companies need to be fully focused on security, and from what I can see, it still often seems like an afterthought."
Source: wired