ChatGPT Mac Plugin Reads iMessages, Raising Privacy and Data‑Exposure Concerns
What Happened — OpenAI released a macOS‑only ChatGPT plugin that can read, search, send, and analyze a user’s Apple iMessages after the user grants the app permission. The AI can summarize conversations and provide communication‑style feedback.
Why It Matters for Compliance & Audit Readiness
- The plugin creates a new data‑processing channel that falls under SOC 2 CC 3.2 (Privacy) and GDPR/CCPA obligations to obtain informed consent before accessing personal communications.
- Continuous‑compliance programs must capture this type of third‑party data access in their vendor‑risk registers and evidence that privacy notices, consent logs, and DSAR processes are in place.
- Verisq’s CookiePLUS capability helps organizations map consent, manage data‑subject requests, and generate audit‑ready evidence for privacy controls.
Who Is Affected — Consumer‑focused SaaS, AI platform providers, enterprises that allow employees to use personal devices for work communications, and any organization handling personal messaging data.
Recommended Actions
- Update your privacy policy and internal consent workflow to cover AI‑driven access to personal messaging data.
- Log every permission grant and maintain an immutable audit trail for SOC 2 CC 3.2 evidence.
- Conduct a DSAR readiness review to ensure you can respond to requests concerning AI‑processed messages.
Source: ZDNet Security
Technical Notes — The plugin operates via macOS system permissions; no CVE is disclosed. It reads the local Messages database, processes text with OpenAI’s inference service, and returns analysis results. Privacy risk stems from the broad scope of data accessed and the lack of granular consent controls. Source: same article