AI Incident Database: OpenAI's ChatGPT Mac App Stored User Data in Unencrypted Text Files
OpenAI's ChatGPT macOS app stored user conversations in plain text. If accessed by a malicious actor, these conversations could have been easily read. The critical security flaw was demonstrated by a third party and ultimately resolved after OpenAI released an update to encrypt the stored data.
AI Incident Database · Incident 757Operator lens (medium): inspect D7 (tool permissions).
Event summary
OpenAI's ChatGPT macOS app stored user conversations in plain text. If accessed by a malicious actor, these conversations could have been easily read. The critical security flaw was demonstrated by a third party and ultimately resolved after OpenAI released an update to encrypt the stored data.
Linked entities
Related graph edges
| Edge | Type | Confidence |
|---|---|---|
| ent-vendor-openai to ent-psf-d1 | maps to | 60% |
| ent-vendor-openai to ent-psf-d1 | maps to | 60% |
| ent-vendor-openai to ent-psf-d1 | maps to | 60% |
| ent-vendor-openai to ent-psf-d2 | maps to | 60% |
| ent-vendor-openai to ent-psf-d2 | maps to | 60% |
| ent-vendor-openai to ent-psf-d2 | maps to | 60% |
| ent-vendor-openai to ent-psf-d6 | maps to | 60% |
| ent-vendor-openai to ent-psf-d6 | maps to | 60% |
| ent-vendor-openai to ent-psf-d6 | maps to | 60% |
| ent-vendor-openai to ent-psf-d2 | maps to | 60% |
| ent-vendor-openai to ent-psf-d2 | maps to | 60% |
| ent-vendor-openai to ent-psf-d2 | maps to | 60% |