ChatGPT's macOS app was storing chats in plain text, but it has been patched
#1
Exclamation 
Quote:A software engineer has discovered that OpenAI's ChatGPT app for Mac was saving chats in plain text. Here is what happened.

In case you missed it, the ChatGPT Mac app was released a week ago for all users. Pedro José Pereira Vieito published his findings on Threads, to reveal that the popular chatbot's desktop app was storing conversations that a user had with the chatbot, in plain text format on the local storage.

ChatGPT for Mac was storing conversations in plain text

The security enthusiast noted that macOS has been blocking other apps from snooping into user data, since macOS Mojave 10.4, which was released 6 years ago. Vieito pointed out that macOS should not be allowing other apps to access the chats, if the app in question was sandboxed. More specifically, ChatGPT's Mac app was saving the data in the following non-protected location: ~/Library/Application\ Support/com.openai.chat/conve…{uuid}/

The researcher had created a special tool to obtain the data, and says that he was successful in extracting the chats without any special permissions from the app or the operating system. So in theory, any app, including malware or an attacker, could access ChatGPT chats without permission from the user. OpenAI acknowledged the fact that its app did not encrypt the data. That might seem alarming, but The Verge reports that the issue has already been patched in an update for the ChatGPT macOS app.

As for why the app didn't use a sandbox, well that is because OpenAI distributes the ChatGPT app for Mac via its own website, instead of distributing it via Apple's Mac App Store. This means that OpenAI does not have to follow the rules set for apps, in this case, it did not need to meet the requirement to sandbox the app and its data.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 3 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Malwarebytes 5.1.11.139
  Malwarebytes 5....Mohammad.Poorya — 16:42
Thunderbird Nebula Version 128.3.2 (esr)
Thunderbird Nebula...harlan4096 — 08:27
Bitdefender 27.0.41.210
Bitdefender’s most...harlan4096 — 08:26
CCleaner 6.29.11342 (16 Oct 2024)
CCleaner 6.29.1134...harlan4096 — 08:24
Intel releases Extreme Tuning Utility 10...
Intel XTU 10 relea...harlan4096 — 08:23

[-]
Birthdays
Today's Birthdays
avatar (46)maggiebz16
Upcoming Birthdays
avatar (46)Michaelaceve
avatar (36)QuadirLigh
avatar (37)Mblippek
avatar (40)guerigGep
avatar (43)viecontAceve
avatar (46)vikgoMam
avatar (39)Michaelcrini

[-]
Online Staff
There are no staff members currently online.

>