The tools we're trusting to build the agent economy can't even protect their own memory.
The Summary
- A security flaw in ChatGPT's Mac app left conversation histories exposed in plain text, allowing any malicious app on the same machine to scrape them without user permission
- OpenAI patched it in July 2024, but the vulnerability window underscores a blindspot: we've been obsessing over AI as threat vector while ignoring AI apps as attack surface
- As agents handle more sensitive work—code, credentials, financial data—poorly secured chat logs become treasure troves for hackers
The Signal
The flaw, discovered by security researcher Pedro José Pereira Vieito, was embarrassingly simple. ChatGPT's Mac app stored conversation histories in plain text without macOS's standard app sandboxing protections. Any other application running on the same Mac could read them. No special permissions needed. No user alert. Just open access to everything you'd ever told ChatGPT.
This isn't theoretical. People use ChatGPT for debugging code that includes API keys. For drafting emails with proprietary strategy. For processing customer data, health information, financial records. The app was a surveillance gift waiting to be unwrapped by malware, spyware, or a motivated insider threat.
"We've been so focused on what AI can steal from us, we forgot to secure what we're feeding it."
OpenAI fixed it after Vieito's responsible disclosure, adding encryption and proper sandboxing in version 1.2024.247. But here's the pattern worth watching:
- ChatGPT's Mac app launched in June 2024
- The vulnerability existed from day one
- It took an outside researcher to find it
- The fix came six weeks after launch
The timeline tells you something about priorities. OpenAI shipped fast, secured slow. And they're not alone. Every AI company is in a feature race. Ship the model, ship the API, ship the desktop app, ship the mobile app, ship the browser extension. Security is a second-sprint problem.
The Implication
As we build toward Web4—where agents act on our behalf, moving money and signing contracts—app security becomes infrastructure security. A compromised chat log today is embarrassing. A compromised agent with wallet access tomorrow is catastrophic.
If you're building with AI tools, treat them like you'd treat any third-party software handling sensitive data. Don't assume the vendor secured it properly. Don't store credentials in conversations. Don't use the same machine for AI experimentation and production work. The attack surface just expanded to include every agent, every assistant, every chatbot you've invited into your workflow.