Vulnerability Description
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://arstechnica.com/ai/2024/07/chatgpts-much-heralded-mac-app-was-storing-co
- https://www.theverge.com/2024/7/3/24191636/openai-chatgpt-mac-app-conversations-
- https://arstechnica.com/ai/2024/07/chatgpts-much-heralded-mac-app-was-storing-co
- https://www.theverge.com/2024/7/3/24191636/openai-chatgpt-mac-app-conversations-
FAQ
What is CVE-2024-40594?
CVE-2024-40594 is a vulnerability with a CVSS score of 2.3 (LOW). The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.
How severe is CVE-2024-40594?
CVE-2024-40594 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-40594?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.