Find notable cyber news and cases, enriched with sources, timelines, and signals.

OpenAI ChatGPT app for Mac unauthorized access vulnerability (CVE-2026-100754)

Vulnerability
First reported
Last updated
Happening score
H score 1
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-100754 exposed OpenAI's ChatGPT app for Mac to unauthorized takeover, putting stored chat logs and other app data at risk. The flaw could let an attacker take over the AI assistant and reach data stored by the app. The vulnerability broadened the risk for Mac users who relied on the app to hold sensitive conversations and related content.

Related Happenings

Apple macOS Full Disk Access access-control tightening

Advisory/Mitigation
H score20 First: 05.10.2026 13:38 Last: 05.10.2026 13:38 Sources 1

How related: Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action.

About this happening: Apple is tightening Full Disk Access in macOS, requiring an explicit user action before apps can gain broad access to files, mail, messages, browsing history, and othe...

Meta Muse Mac hidden dictation endpoint security flaw

Vulnerability
H score37 First: 22.09.2026 09:33 Last: 22.09.2026 09:33 Sources 1

How related: The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said.

About this happening: Meta's Muse assistant for Mac has a now-patched flaw that let an unprivileged local process redirect dictation traffic, capture dictated audio and prompts, inject trus...

ChatGPT planted-instruction cross-account data exfiltration security flaw

Vulnerability
H score25 First: 08.09.2026 17:19 Last: 08.09.2026 17:19 Sources 1

About this happening: ChatGPT was shown to accept a planted instruction that could trigger hidden tool use and cross-account data exfiltration from connected apps, including Gmail. In t...

IPhone AI chatbot traffic leak of API keys, replayable tokens, and open relays

Technical Analysis
H score27 First: 30.06.2026 16:49 Last: 30.06.2026 16:49 Sources 1

About this happening: LLMKeyLens testing found 444 iPhone AI chatbot apps leaking paid AI access, exposing API keys, replayable tokens, and open relays that let others bill mode...

ChatGPT single-prompt DNS side-channel exfiltration remote code execution flaw

Vulnerability
H score33 First: 31.03.2026 16:01 Last: 31.03.2026 16:01 Sources 1

About this happening: A ChatGPT vulnerability let a single malicious prompt covertly exfiltrate prompts, messages, uploaded files, and other sensitive content through a DNS side channel. Th...

Timeline

  1. 05.10.2026 13:38 2 articles · 2h ago

    CVE-2026-100754 exposes OpenAI's ChatGPT app for Mac to assistant takeover

    Initial Disclosure

    Security researcher Patrick Wardle was acknowledged for reporting CVE-2026-100754 in OpenAI's ChatGPT app for Mac. The vulnerability could be abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.

    Show sources