
Source: Fortune
Summary
ChatGPT now has a new Apple Messages plugin that allows users to search old texts, summarize group chats, and draft replies from a Mac. The plugin requires user approval for access, but others in the conversations are not notified. Security expert Paul Walsh called the integration “one of the most dangerous things I have seen in technology,” warning it could function like spyware. OpenAI claims the plugin runs locally by default and only accesses messages when a user explicitly requests it. However, Walsh argues that once a user grants access, it can expose messages from people who never agreed to the integration.
Our Reading
The announcement sounds familiar.
ChatGPT gains access to iMessage without user consent for others.
OpenAI says data stays local, but risks remain.
Privacy experts warn of third-party access to private messages.
AI’s growing access to personal data raises new security concerns.
Author: Evan Null
When private messages become searchable
The ability to share a private message with a third party isn’t completely new. Someone can screenshot a text, forward it, or copy and paste it into ChatGPT. What changes with the Messages plugin is how easily an AI can search information across conversations once a user grants it access.
Walsh argues that distinction matters because the person granting the access isn’t the only person whose information appears in those conversations.
“That’s you breaking that person’s trust,” Walsh said in reference to taking a screenshot. “It’s not you allowing a third party inside the conversation.”
Dave Richardson, CTO at mobile security company Lookout, told Fortune he could understand why some might compare the integration to spyware, though he believes the term is “a little too strong.”
Still, Richardson said enabling the integration introduces “significant risk” to what has historically been considered a secure channel for communication.
OpenAI says Messages stay local by default
There are important limits to how much access the integration gives OpenAI.
ChatGPT only reads Messages after a user makes a request that specifically requires information from them, according to the company. Asking ChatGPT to summarize messages from a conversation with a particular contact, for example, would cause it to read that thread.
ChatGPT desktop stores conversations locally on the user’s computer by default, according to OpenAI. Messages content included in those conversations is therefore not automatically synced to the company’s servers.
If a user chooses to store a ChatGPT conversation in the cloud, however, relevant Messages content follows the same retention policies as other content in that conversation.
That distinction is central to Walsh’s most serious warning. He argues that if content from an encrypted conversation is stored on another company’s servers, it could create another potential point of access for hackers, insiders, governments, or law enforcement.
AI gets access to more than the chatbox
The Messages integration comes amid a broader expansion in the data and device capabilities AI services are seeking access to.
In research provided to Fortune, Lookout said its analysis of more than 420 million Android and iOS applications shows the permissions and capabilities of AI-related apps have continued to grow over the past year.
The Messages plugin uses existing macOS capabilities rather than a new iMessage API built by Apple specifically for ChatGPT, according to OpenAI. Its setup requires users to approve AppleScript, Accessibility, and Full Disk Access.
Fortune asked Apple whether it anticipated existing macOS permissions being used to give AI agents the ability to read and search Messages and whether it is considering additional safeguards as AI agents gain access to sensitive applications.
Apple did not immediately respond to Fortune’s request for comment.
Privacy concerns extend beyond ChatGPT
Walsh said the risks created by third-party software accessing sensitive information aren’t unique to ChatGPT or AI. What is changing, he argues, is the amount of information AI can rapidly search and analyze once it has that access.
“I would never build an iMessage integration that has the ability to read messages ever,” Walsh said, “Because it breaks the fundamental protections that end-to-end encryption brings.”
As AI agents become more capable, much of their usefulness will come from gaining access to more of people’s digital lives—and the complication is that those lives overlap.
With Apple Messages, one person can give an AI access to years of conversations that were written by plenty of people who never agreed to let it in.
Security and privacy experts continue to raise concerns about the implications of AI gaining access to personal data through third-party integrations.








