A security vulnerability in the initial releases of OpenAI's ChatGPT desktop application for macOS left user chat histories exposed in unencrypted plain text. This flaw meant that conversations with the AI chatbot were stored locally on the system in an easily accessible format. Security researchers identified that the application bypassed Apple's native sandboxing restrictions, which are designed to isolate applications and prevent unauthorized data access. As a result, any other local process or malicious application could have accessed these sensitive logs without explicit user permission.
The issue was initially discovered by Threads user Pedro José Pereira Vieito, who demonstrated how the unencrypted conversations could be readily accessed. OpenAI distributed the ChatGPT Mac app directly from its website, rather than through Apple's Mac App Store. This distribution method meant the app was not subject to the same stringent security guidelines and notarization processes that Apple enforces for apps within its official store, which include proper sandboxing.
Upon becoming aware of the vulnerability, OpenAI released an emergency software update to encrypt conversation histories stored on Mac devices. The company urged users of the ChatGPT macOS app to download the latest version or reinstall the application to secure their data. An OpenAI spokesperson stated the company is committed to maintaining high security standards as its technology evolves.
This incident is not the first security concern for OpenAI's macOS applications. In a separate event, OpenAI confirmed a security incident in April 2026 related to a third-party developer library, Axios JavaScript, used by its macOS apps. This incident prompted the revocation and rotation of OpenAI's macOS security certificates, requiring all Mac users to update their OpenAI applications, including ChatGPT, by May 8, 2026. OpenAI stated that while limited credential material was exfiltrated from code repositories on two employee devices, they found no evidence of user data access or compromise of production systems in that instance.
The recent plaintext storage vulnerability highlights the ongoing security challenges associated with rapidly developing AI software. It also underscores the importance of robust security measures in applications that handle personal or confidential information, particularly as AI tools become more integrated into daily workflows.
