First published: Sat Jul 06 2024(Updated: )
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenAI API | <2024-07-05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-40594 is classified as high due to the risk of sensitive conversation data being accessed by unauthorized applications.
To fix CVE-2024-40594, upgrade to the ChatGPT app version released after July 5, 2024, which addresses the sandboxing and data storage issues.
CVE-2024-40594 affects conversation data that is stored in cleartext, making it vulnerable to exposure.
Users of the OpenAI ChatGPT app for macOS prior to July 5, 2024, are affected by CVE-2024-40594.
Opting out of the sandbox in CVE-2024-40594 means that the application does not have the added security layer that restricts its access to the system and other apps.