CVE-2024-40594: Low severity chatgpt vulnerability
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40594?
The severity of CVE-2024-40594 is classified as high due to the risk of sensitive conversation data being accessed by unauthorized applications.
How do I fix CVE-2024-40594?
To fix CVE-2024-40594, upgrade to the ChatGPT app version released after July 5, 2024, which addresses the sandboxing and data storage issues.
What type of data is affected by CVE-2024-40594?
CVE-2024-40594 affects conversation data that is stored in cleartext, making it vulnerable to exposure.
Who is affected by CVE-2024-40594?
Users of the OpenAI ChatGPT app for macOS prior to July 5, 2024, are affected by CVE-2024-40594.
What does opting out of the sandbox mean in CVE-2024-40594?
Opting out of the sandbox in CVE-2024-40594 means that the application does not have the added security layer that restricts its access to the system and other apps.