ChatGPT Integrates with Apple iMessage, Raising Privacy Concerns

icon币界网
Share
AI summary iconSummary
OpenAI has added an Apple iMessage plugin to ChatGPT for Mac, enabling users to search messages, draft replies, and send texts. The feature requires user approval but does not notify others in the conversation. Experts warn that third-party access could expose private messages, even with iMessage encryption. OpenAI states that data remains local by default but is sent to the cloud if users opt in. Lookout and Proton have raised concerns about AI accessing sensitive chats. As the Fear and Greed Index fluctuates, reflecting market unease, altcoins to watch may face pressure from such technological developments.
CoinDesk reports:

After OpenAI added the Messages plugin to ChatGPT’s desktop version, users can now have the chatbot search through old texts, summarize group chats, draft replies, and send messages directly on Mac. The feature requires manual authorization from the installer, but other participants in the same conversation are not notified, sparking immediate privacy and security concerns.

Focus on access after decryption

Several security experts have pointed out that the issue is not that ChatGPT broke Apple’s end-to-end encryption, but rather that once messages reach the recipient’s device, their content can be accessed by local software. In other words, the encrypted transmission itself remains intact, but if third-party tools gain device access, content originally visible only to the two parties in the conversation may be retrieved and analyzed by additional systems.

Security and privacy expert Paul Walsh told Fortune that the most concerning aspect of this type of access is that the authorized user doesn’t just expose their own data—they also expose conversations from others in their years of chat history to third-party systems. For individuals who rely on encrypted communication for sensitive matters, this undermines their expectation of private communication.

OpenAI states that defaults are retained locally.

OpenAI states that after enabling plugins, ChatGPT does not automatically index user information records or actively read through all conversations. The system only accesses specific messages when the user explicitly requests information related to their content.

The company also stated that the desktop version of ChatGPT saves relevant conversations locally by default, and content from Apple Messages will not automatically sync to OpenAI’s servers. However, if users choose to save ChatGPT conversations to the cloud, these messages will be subject to the same storage and retention policies and may also be included in the cloud memory feature.

  • By default, message content is stored locally on the user's Mac.
  • The system will only access the information after a clear question is asked.
  • If the conversation is saved to the cloud, the related content will also be stored in the cloud.

Security companies are concerned about the continued expansion of permissions.

Dave Richardson, Chief Technology Officer at mobile security company Lookout, said it might be overly strong to label this feature directly as "spyware," since it is disabled by default and requires explicit user authorization. However, he also noted that it still poses a significant risk to communication channels previously considered secure.

He noted that end-to-end encryption protects messages while they are in transit between devices, preventing the platform or network operator from accessing the content en route—but once the message reaches the device, the device itself can still access it. If users then share this content with third-party services like OpenAI or Anthropic, the actual scope of protection provided by end-to-end encryption is reduced.

Privacy company Proton also released an analysis on Tuesday stating that such risks can spill over to individuals who have never used ChatGPT, as their messages may be accessible if the other party in the conversation has enabled plugins. Proton also noted that the requirement for “full disk access” during installation represents a broader security concern.

AI is entering more sensitive applications.

This controversy also reflects how AI tools are moving beyond chat interfaces to deeper device permissions. Research provided by Lookout to Fortune shows that over the past year, AI-related apps have consistently requested more data permissions and high-risk capabilities, with similar trends expanding on iOS.

OpenAI explains that this plugin is not a new iMessage interface built by Apple specifically for ChatGPT, but rather leverages existing capabilities in macOS. During installation, users must grant permissions for AppleScript, accessibility features, and full disk access.

As AI agents gain greater control over devices, the debate is no longer just about whether users are willing to grant authorization, but also whether other participants in a conversation are aware, and whether private communications, once retrieved, summarized, and stored long-term by AI, could create new data exposure pathways.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.