OpenAI Issues Urgent Security Update for Mac Apps After Supply Chain Attack

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

OpenAI detected a security vulnerability in its Mac applications due to a compromised external development tool, Axios, linked to a broader software supply chain attack. While no user data or systems were breached, OpenAI urged users to update their apps to prevent risks from counterfeit applications.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the development and use of AI systems (OpenAI's ChatGPT Mac applications) and a security breach in the software supply chain that could plausibly lead to harm such as unauthorized access, counterfeit applications, or compromised user security. Although no actual harm (data breach, system compromise) was found, the incident posed a credible risk to the integrity and security of AI systems and their users. Therefore, it fits the definition of an AI Hazard rather than an AI Incident. The company's response and updates are mitigating the risk, but the event itself is about a plausible threat rather than realized harm.[AI generated]
AI principles
Robustness & digital security

Industries
Consumer servicesDigital security

Affected stakeholders
Consumers

Harm types
Other

Business function:
Citizen/customer service

AI system task:
Interaction support/chatbots


Articles about this incident or hazard