HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

ChatGPT Mac Plugin Reads iMessages, Raising Privacy and Data‑Exposure Concerns

OpenAI’s macOS ChatGPT plugin can read, search, send, and analyze a user’s iMessages after permission is granted, creating a potential privacy exposure. This matters for SOC 2 privacy compliance and requires consent, audit logging, and DSAR readiness.

LiveThreat™ Intelligence · 📅 August 21, 2026· 📰 zdnet.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
zdnet.com

ChatGPT Mac Plugin Reads iMessages, Raising Privacy and Data‑Exposure Concerns

What Happened — OpenAI released a macOS‑only ChatGPT plugin that can read, search, send, and analyze a user’s Apple iMessages after the user grants the app permission. The AI can summarize conversations and provide communication‑style feedback.

Why It Matters for Compliance & Audit Readiness

  • The plugin creates a new data‑processing channel that falls under SOC 2 CC 3.2 (Privacy) and GDPR/CCPA obligations to obtain informed consent before accessing personal communications.
  • Continuous‑compliance programs must capture this type of third‑party data access in their vendor‑risk registers and evidence that privacy notices, consent logs, and DSAR processes are in place.
  • Verisq’s CookiePLUS capability helps organizations map consent, manage data‑subject requests, and generate audit‑ready evidence for privacy controls.

Who Is Affected — Consumer‑focused SaaS, AI platform providers, enterprises that allow employees to use personal devices for work communications, and any organization handling personal messaging data.

Recommended Actions

  • Update your privacy policy and internal consent workflow to cover AI‑driven access to personal messaging data.
  • Log every permission grant and maintain an immutable audit trail for SOC 2 CC 3.2 evidence.
  • Conduct a DSAR readiness review to ensure you can respond to requests concerning AI‑processed messages.

Source: ZDNet Security

Technical Notes — The plugin operates via macOS system permissions; no CVE is disclosed. It reads the local Messages database, processes text with OpenAI’s inference service, and returns analysis results. Privacy risk stems from the broad scope of data accessed and the lack of granular consent controls. Source: same article

📰 Original Source
https://www.zdnet.com/article/chatgpts-new-mac-plugin-analyzed-my-imessages-and-i-found-it-surprisingly-useful/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →