ChatGPT macOS App Vulnerability Exposes User Conversations

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A vulnerability in the ChatGPT app for macOS, discovered by developer Pedro José Pereira Vieito, exposed user conversations by storing them in plain text without encryption. This posed a significant privacy risk. OpenAI quickly addressed the issue by releasing an update that encrypts stored conversations, enhancing user data protection.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (ChatGPT) and a security flaw in its macOS app that exposed user conversations, which constitutes a privacy and data security harm. Since the harm (exposure of conversations) has occurred due to the app's design and storage method, this qualifies as an AI Incident. The update fixing the flaw is a response to this incident. Therefore, the event is classified as an AI Incident because the AI system's use led to a direct harm (privacy breach).[AI generated]
AI principles
Privacy & data governanceRobustness & digital securityRespect of human rightsAccountability

Industries
Consumer servicesDigital securityIT infrastructure and hosting

Affected stakeholders
Consumers

Harm types
Human or fundamental rightsReputationalPsychologicalEconomic/Property

AI system task:
Interaction support/chatbotsContent generation

In other databases

Articles about this incident or hazard