ChatGPT gains ability to control iMessage on macOS, raising questions about Apple data security
Read more
Ventureburn
ventureburn.com

ChatGPT gains ability to control iMessage on macOS, raising questions about Apple data security

Amid rising costs for building artificial intelligence infrastructure, software developers are striving to demonstrate the practical utility of their tools by integrating AI into everyday desktop applications. Now, with a new macOS plugin, ChatGPT can manage iMessage, allowing the chatbot to search message history, draft replies, and send messages directly from the user's Mac computer.

This integration offers significant convenience, yet it grants a third-party tool unrestricted access to Apple's secure ecosystem. This situation has sparked widespread discussion among Mac users and security experts regarding privacy concerns.

OpenAI developed this specialized plugin for Apple Messages for its desktop application on macOS, targeting subscribers of Codex and ChatGPT Work plans. The plugin utilizes native macOS tools, such as AppleScript and accessibility services, enabling it to function locally on the user's device. The AI can view past text messages, generate responses, and control dialogue threads in iMessage, SMS, and RCS. Users can employ the chatbot to review missed group chats, extract dates from old messages, or quickly compose follow-up replies.

The system is set by default so that every outgoing message requires individual permission. However, users wishing to bypass this confirmation process for faster, autonomous messaging can disable this feature.

To ensure the integration works, Mac owners must grant ChatGPT broad access rights to the entire operating system. The setup process involves enabling full disk access in Mac system settings, as well as granting access to contact lists and system automation tools. It should be noted that some built-in protection mechanisms do not apply to the message database file when read locally via iMessage, which is transmitted using end-to-end encryption. Nevertheless, full disk access allows the application to access local backups, Safari web activity logs, and Mail records.

OpenAI emphasizes that the plugin operates locally and does not create a persistent index of user texts. Despite this, granting extensive system privileges opens up new vulnerability vectors in case the Mac is compromised. This launch occurs amid a tense period between the two tech companies, as Apple recently sued OpenAI, alleging that its employees were stolen and illegally poached.

Apple traditionally maintains strict control over its messaging service and previously even fired competitors attempting to integrate with this service, such as Beeper Mini. Furthermore, Apple is developing its own Siri-based AI capabilities that will process messages directly on the device. OpenAI's entry into Apple's territory by launching a Mac plugin that manages Apple Messages may prompt Apple to restrict third-party automation privileges in future macOS updates.

For professionals who constantly interact with clients, automated searching and message drafting provide an obvious boost in efficiency. However, privacy advocates warn about the risks of giving external software full access to sensitive personal message history. If a user decides to use the plugin, it is recommended to keep the manual message approval setting active so that texts are never sent without explicit consent. It is also advised to regularly check Mac privacy settings. Ultimately, saving a few seconds on correspondence should not require giving up control over one's private digital life.

Popular