The ChatGPT desktop app for Mac just got hit with a security breach
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get the latest gadgets delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

OpenAI’s ChatGPT desktop app for Mac experienced a security breach involving two employee devices. The company is issuing a software update and investigating, but assures no user data was accessed. The update rollout begins immediately, with full deployment by June 12.

OpenAI’s ChatGPT desktop app for Mac has been affected by a security breach involving two employee devices, prompting the company to issue an urgent software update and initiate an investigation. The incident is significant because it concerns a widely used AI tool and raises questions about data security and software integrity.

According to a report by 9to5Mac, OpenAI identified malicious activity linked to a security issue involving a compromised open-source library. The breach impacted two employee devices, but OpenAI states that no user data was accessed or systems compromised. The company responded swiftly by working with a third-party digital forensics firm to investigate the incident. An immediate software update for the Mac app is being rolled out now, with a full deployment scheduled for June 12. Users on other platforms, such as Windows and iOS, are not affected and do not need to take action at this time. This is not the first security concern related to the ChatGPT Mac app; in 2024, it was found to store user conversations in plain text, raising ongoing security questions.

Why It Matters

This incident highlights ongoing cybersecurity risks associated with widely used AI applications and the importance of prompt response and transparency from companies like OpenAI. For users, it underscores the need to stay updated with software patches and be aware of potential vulnerabilities. The breach also raises broader concerns about open-source code security and the potential impact on user trust and data privacy.

Amazon

Mac security software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

OpenAI’s ChatGPT Mac app, launched in 2024, has faced previous security issues, including insecure local storage of user conversations. The current breach involves a compromised open-source library, which is a common component in software development but can introduce vulnerabilities if not properly secured. The incident occurs amid increasing scrutiny of AI security and data privacy practices. The company’s swift response and ongoing investigation aim to mitigate potential damage and reassure users.

“Upon identification of the malicious activity, we worked quickly to investigate, contain and take steps to protect our systems.”

— OpenAI spokesperson

“We confirmed that only limited credential material was successfully exfiltrated from these code repositories and that no other information or code was impacted.”

— OpenAI blog

What Remains Unclear

It is still unclear how the malicious activity originated, whether additional devices or systems are at risk, and what specific open-source library was compromised. OpenAI has not detailed the full scope of the investigation, and further updates are expected as the inquiry progresses.

What’s Next

OpenAI will continue its investigation with the third-party forensics firm and is expected to release more detailed findings. The company plans to monitor for any further security issues and will provide additional guidance to users as needed. The full rollout of the software update for Mac users is scheduled to complete by June 12, and users are advised to update promptly.

Key Questions

What exactly happened in the security breach?

OpenAI identified malicious activity involving two employee devices linked to a compromised open-source library, but states that no user data was accessed or systems compromised.

Should I update my ChatGPT Mac app now?

Yes, users are encouraged to update the app when prompted to ensure they have the latest security patches.

Does this affect users on other platforms?

No, users on Windows and iOS are not affected at this time and do not need to take any action.

Will there be more security updates or investigations?

Yes, OpenAI is continuing its investigation and will provide further updates as they become available.

Could my data have been accessed?

According to OpenAI, there is no evidence that user data was accessed during this incident.

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Nvidia CEO’s Charitable Foundation Signs GPU Deal With CoreWeave

Nvidia CEO’s charitable foundation has signed a GPU supply agreement with CoreWeave, marking a significant development in AI and cloud computing infrastructure.

Ingrid Andress National Anthem Free with AU Rich 20

Experience Ingrid Andress’s stirring rendition of the national anthem. Access it free now, enhanced with AU-rich element 20 audio quality.

Expanding Our Support For Scientists – Anthropic

Anthropic announces expansion of support for scientists, but details on resources, eligibility, and timing remain undisclosed, raising questions about practical impact.

I turned a $80 RK3562 Android tablet into a Debian Linux workstation

A user successfully installed Debian 12 on an $80 RK3562-based Android tablet, turning it into a Linux workstation without official support.