CVE-2026-100754 affects a script interpreter in OpenAI's ChatGPT app for macOS. The interpreter accepted external commands that could be injected into the trusted ChatGPT process, abusing the operating system's trust in that process. Exploitation required a user to execute malicious code locally and could allow an attacker to take over the assistant and access its entire conversation history and other stored data. OpenAI fixed the vulnerability in an update released in late September 2026.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in OpenAI's ChatGPT Mac app that could allow attackers to take over the assistant, access chat logs and other stored data, and make it execute commands appearing to originate from legitimate OpenAI software. The reported exploit required roughly a dozen lines of code. OpenAI has patched the flaw.
A vulnerability in OpenAI's ChatGPT app for Mac that could allow an attacker to take over the AI assistant and gain unauthorized access to chat logs and other application data. The article does not describe the underlying technical flaw or exploitation prerequisites.
A vulnerability in the ChatGPT app for macOS allowed locally executed malicious code to inject commands through a script interpreter into the trusted ChatGPT process. According to the report, launching the interpreter three times enabled exploitation, potentially exposing the entire conversation history and other data accessible under the app's permissions. Exploitation required the user to execute malicious code locally. OpenAI fixed the issue in an update in late September; whether actual attacks occurred is unknown.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.