Borrowed Trust on the Desktop — CVE-2026-100754 and the ChatGPT macOS Trust Boundary
OpenAI documented the fix for CVE-2026-100754 on 25 September 2026: a flaw in ChatGPT for macOS that let unprivileged code already running on the machine act through the application's own trusted components. The fixed build is 26.924.20706, credited to Patrick Wardle of the Objective-See Foundation, with a detailed public account in WIRED on 2 October. No victims, no confirmed data theft, and no exploitation in the wild have been reported — and those limits are load-bearing. What makes this worth covering is not the blast radius. It is the shape of the bug: the desktop AI agent has become a privilege level, and this is what happens when the check guarding it fails open.
Signatures, ancestry, and the interpreter that bridged them
Per WIRED's account of the Objective-See research, components of the ChatGPT macOS app decided whether another local process should be trusted using digital signatures and process ancestry — the chain of processes an action originated from. Those checks exist to separate genuine OpenAI software from unrelated code on the same machine. The failure was a trusted script interpreter that would accept an untrusted script and deliver it into the main ChatGPT process. Local unprivileged code could thereby appear inside a process chain the application accepted, and invoke capabilities reserved for trusted ChatGPT components.
Note what this is not: not prompt injection, not a model defect, not a server-side flaw. It is a desktop application trust-boundary failure — the same class Wardle's team keeps finding where agents meet operating systems, including the Meta Muse macOS flaw covered here last month. Objective-See's own framing is that AI agents now belong in the desktop threat model alongside malware: agents need deep system access to do anything useful, and that access is inheritable by whatever subverts them.
Potential reach is not confirmed theft
WIRED reported the flaw could potentially expose chat logs and enable requests involving browser sessions or other sensitive applications while appearing to originate from trusted OpenAI software. That is potential impact demonstrated by a researcher-built proof of concept — not a compromise. Neither OpenAI's notice nor the WIRED reporting identifies unauthorised access, exfiltration, an affected organisation, or a campaign, and OpenAI's notice assigns no severity or CVSS score and publishes no affected-version range. Version 26.924.20706 is confirmed fixed; that alone does not establish every earlier build was vulnerable.
Scope discipline matters here too. The evidence establishes a macOS desktop-app issue. It does not establish that the Windows application, the web service, Codex, or any other OpenAI product was affected, and the reporting provides no complete account of which permissions or integrations each potential action required — practical reach likely differs between installations. Readers who saw claims extending this to Windows should treat those as unconfirmed: the reviewed vendor and research reporting does not support them.
Why a local-only bug still matters to agent security
The local-code prerequisite narrows the threat model to machines where the attacker already runs something — but that is precisely the foothold infostealers already buy. This site tracked Vidar harvesting Claude Code credentials and the lockdown-mode response; commodity Mac stealers landing first and escalating through the agent's trust second is a two-stage chain defenders should now assume exists. A process that cannot read your chats directly borrowing the one process that can is the desktop analogue of the confused-deputy problems this site covers in MCP and agent tooling every week.
What to do
- Verify build 26.924.20706, not just the release label. OpenAI described the fix under the macOS security update 26.924, but the complete verified build is 26.924.20706. Managed Mac fleets should confirm the full installed build — the sources document no universal auto-update guarantee or adoption figures.
- Treat desktop agents as a privilege tier in your threat model. Inventory which local applications hold chat history, credentials, browser-adjacent sessions and file access, and assume commodity malware will attempt to borrow that standing. Endpoint controls should watch for unusual child processes and IPC into agent applications, not just the agents' network traffic.
- Do not extrapolate beyond macOS. Until OpenAI or Objective-See publishes a fuller advisory, there is no evidenced basis for action on Windows, web, or Codex deployments for this CVE. Track the primary sources below for the affected range and any severity assignment.
- Ask agent vendors how local trust is established. Signature checks, ancestry checks, and XPC/service boundaries are exactly where these bugs live. "The OS handles it" is not an answer when a trusted interpreter accepts untrusted input.
Our verification was documentary and primary-source-led. We fetched and read in full a detailed secondary account of the research (fix date 25 September 2026, build 26.924.20706, Wardle/Objective-See credit, signature-and-ancestry mechanism, trusted-interpreter path, potential chat-log and browser-session impact, absence of confirmed exploitation, no CVSS or affected range), and cross-checked the CVE identifier, fixed build, credit line and disclosure timeline against three independent secondary reports plus OpenAI's Codex changelog entry. We deliberately scoped impact claims to what the reviewed reporting supports and flagged the Windows-extrapolation gap. We did not run the ChatGPT app, reproduce the proof of concept, or contact any third-party system.
Sources:
- WIRED — "A Flaw in ChatGPT's Mac App Could Have Let Hackers Grab Sensitive Data" (2 October 2026; Objective-See research, trusted script interpreter, chat-log and browser-session impact)
- The Hack Academy — "OpenAI fixes reported local trust flaw in ChatGPT for macOS" (2 October 2026; fix date, build number, scope limits, no-CVSS and no-range gaps)
- ForkLog — "Vulnerability in ChatGPT macOS App Allowing Access to Conversations Fixed" (masquerade-as-trusted-component mechanism, conversation access)
- OpenAI Codex changelog via Releasebot — CVE-2026-100754 fixed on macOS in 26.924.20706, crediting Patrick Wardle, Objective-See Foundation