Security/shipped/2026-09-25

Security vulnerability found and fixed in ChatGPT's macOS application

A critical security vulnerability was discovered in the ChatGPT application for macOS, which could have allowed local privilege escalation and unauthorized access to sensitive user data, including chat history. OpenAI, the developer of ChatGPT, confirmed the existence of the flaw and promptly released an update to address it. The company advised all users to update their application to the latest version to mitigate the risk. OpenAI stated that there was no evidence of the vulnerability being actively exploited in the wild. This information was confirmed by OpenAI, the sole source for the vulnerability's discovery and fix.

5 articles from 5 outlets covered this story. No difference in framing or figures was found between them. The underlying claim is sourced from a shipped.

What do all outlets agree on?

5 outlets covered “Security vulnerability found and fixed in ChatGPT's macOS application”. All of them report the following:

  • Security vulnerability in ChatGPT macOS app
  • Vulnerability allowed local privilege escalation
  • Could expose sensitive user data, including chat history
  • OpenAI confirmed the flaw
  • OpenAI released a fix/update
  • Users advised to update the app
  • No evidence of active exploitation

Did outlets disagree about this?

No. All 5 outlets covering “Security vulnerability found and fixed in ChatGPT's macOS application” reported it the same way — no difference in framing or figures was found between them.

Which outlets covered this?

All 5 articles found on this story, grouped by the stance of the piece. Every link goes to the original publisher.

What related stories are there?

Which companies does this involve?

Get the week in AI in one email

What happened, which outlets reported it, and where their coverage differed. One issue a week.

The first issue hasn’t gone out yet. Subscribe and it’s the one you’ll get.

We’ll send the digest and nothing else. One-click unsubscribe. Privacy.