OpenAI has added apple information plugins to the ChatGPT desktop to allow chat robots on Mac to search for old text messages, wrap group conversations, draft responses and send messages directly. This function requires a manual authorization from the installer, but other participants in the same dialogue will not receive a reminder, which quickly triggers privacy and security disputes.
Focus on access after decryption
According to several security sources, the controversy was not that ChatGPT had broken the end-to-end encryption of apples, but that after the message reached the recipient ' s device, the content was already read by local software. In other words, the encrypted transmission itself has not been destroyed, but once third-party tools have acquired the right to equipment, what would otherwise have been visible between the two interlocutors may have been retrieved and analysed by additional systems.
Paul Walsh, an expert in security and privacy, said to Fortune that the most worrying aspect of such access was that the author did not simply open up his own data, but also exposed to third-party systems the statements of others in years of conversation. For those who rely on encrypted communications to handle sensitive matters, this weakens their expectations of private communication.
OpenAI says the default is left locally
OpenAI states that after the plugin is enabled, ChatGPT does not automatically create an index for user information records and does not proactively read all conversations. Only when a user explicitly sends a request related to the content of the message will the system access the corresponding message.
The company also stated that the ChatGPT desktop version had by default saved the conversation on a local computer and that the content from apple information was not automatically synchronized to the OpenAI server. However, if the user chooses to save the ChatGPT dialogue to the cloud, the message content will apply the same storage and retention rules and may enter the cloud memory function.
- Save message content on user Mac local by default
- The system will only access the content of the information once the question is clearly asked.
- If the conversation turns into a cloud, the content goes into a cloud.
The security company is worried about the extension.
According to Dave Richardson, Chief Technical Officer of the mobile security company Lookout, this function may be referred to directly as “spying software” because it is implicitly closed and requires a clear user authorization. At the same time, however, he believes that this still poses a clear risk to the channels of communication that were supposed to be considered safe.
He noted that end-to-end encryption protected the transmission of information between devices and that the platform or network operator could not read content in the course of the journey, but that the device itself was still accessible when the message reached the terminal. If the user opens these content to third parties such as OpenAI or Anthropic, the actual end-to-end encryption protection will be reduced.
The privacy company Proton also released an analysis on Tuesday that such risks would spill over to people who had never used ChatGPT, as their messages could also be accessed as long as the other party to the dialogue had activated the plugin. Proton also mentioned that the “full disk access rights” that needed to be granted during the installation process were in itself broader security considerations.
AI is entering more sensitive applications.
This controversy also reflects the fact that the AI tool is moving from chat box to deeper device privileges. The research provided by Lookout to Fortune shows that data access and high-risk capacity for AI applications has continued to increase over the past year, as has the trend on the iOS platform.
OpenAI explains that this plugin is not the new iMessage interface created by Apple for ChatGPT, but calls for the macOS capability available. At the time of installation, the user needs to grant access to AppleScript, assistive functions and complete disk access.
As AI agents gain more control over equipment, the dispute is no longer just “is the user willing to authorize” but also includes the knowledge of other participants in a dialogue and the possibility of new data exports following the retrieval, summary and long-term preservation of private communications by AI.
