ChatGPT no longer has to wait for people to copy and paste their texts into the chatbot. Now it can search for them itself.
A new Apple Messages plugin lets ChatGPT search old texts, summarize group chats, draft replies, and send messages from a Mac. The person installing it has to approve the access—but everyone else in those conversations does not.
That is opening a new front in the privacy and security debate about AI agents as they gain access to increasingly sensitive parts of people’s digital lives. Security and privacy expert Paul Walsh calls the Messages integration “one of the most dangerous things I have seen in technology” and warns it can function like spyware for people who depend on private communications.
But according to OpenAI, the plugin runs locally by default, only reads Messages when a user explicitly asks it to, and does not automatically upload or index a user’s message history. But one person’s decision to opt in can make years of conversations searchable by AI, including messages from people who never agreed to give it access.
Explaining what would happen if he enabled the integration himself, Walsh told Fortune: “Every single person I send a message to through iMessage will never know that I have a third party inside that application, and they will never be notified.”
For people who deliberately use encrypted messaging for sensitive conversations, he said, “it becomes dangerous.”
OpenAI rolled out the plugin last week for ChatGPT on Mac, allowing users to search iMessage, SMS, and RCS conversations, catch up on threads, draft replies, and send them through Apple Messages. Users must explicitly install the plugin and grant ChatGPT several macOS permissions, including AppleScript, Accessibility, and Full Disk Access.
According to OpenAI, ChatGPT does not create an index of a user’s Messages or begin reading conversations simply because the plugin has been enabled. The company added that a user must make a request that specifically seeks information from Messages before ChatGPT will access them.
Walsh’s concern isn’t that ChatGPT has cracked Apple’s end-to-end encryption. Instead, it centers on what happens after an encrypted message reaches its intended recipient and becomes readable on that person’s Mac. He compares giving ChatGPT that access to installing spyware, arguing the encryption itself can remain intact while another piece of software gains access to the readable messages.
“Let’s say we agree it’s encrypted. Perfect mathematics hasn’t been broken,” Walsh said. But once another system can read a message before it is encrypted or after it has been decrypted, he said, “you have broken the fundamental concept.”
When private messages become searchable
The ability to share a private message with a third party isn’t completely new. Someone can screenshot a text, forward it, or copy and paste it into ChatGPT. What changes with the Messages plugin is how easily an AI can search information across conversations once a user grants it access.
Walsh argues that distinction matters because the person granting the access isn’t the only person whose information appears in those conversations.
“That’s you breaking that person’s trust,” Walsh said in reference to taking a screenshot. “It’s not you allowing a third party inside the conversation.”
Dave Richardson, CTO at mobile security company Lookout, told Fortune he could understand why some might compare the integration to spyware, though he believes the term is “a little too strong.” Spyware typically accesses and steals information without a user’s permission, he said, while the Messages feature is off by default and requires users to explicitly grant access.
Still, Richardson said enabling the integration introduces “significant risk” to what has historically been considered a secure channel for communication.
End-to-end encryption protects a message as it travels between devices, Richardson explained, preventing the network operator or platform provider from reading or modifying it. But the devices on either end can still access the message once it arrives.
“By granting third parties such as OpenAI or Anthropic access to these messages, you’re losing many of the benefits that end-to-end encryption has to offer,” Richardson said.
Privacy-focused technology company Proton raised similar concerns in an analysis published Tuesday, warning the privacy implications can extend to people who never use ChatGPT because their messages can still be accessed when someone they communicate with uses the plugin. Proton also pointed to Full Disk Access, one of the macOS permissions required during setup, as a broader security consideration.
OpenAI says Messages stay local by default
There are important limits to how much access the integration gives OpenAI.
ChatGPT only reads Messages after a user makes a request that specifically requires information from them, according to the company. Asking ChatGPT to summarize messages from a conversation with a particular contact, for example, would cause it to read that thread.
ChatGPT desktop stores conversations locally on the user’s computer by default, according to OpenAI. Messages content included in those conversations is therefore not automatically synced to the company’s servers. If a user chooses to store a ChatGPT conversation in the cloud, however, relevant Messages content follows the same retention policies as other content in that conversation. Conversation data may remain in cloud storage until a user deletes it and may also inform Memories stored in the cloud.
That distinction is central to Walsh’s most serious warning. He argues that if content from an encrypted conversation is stored on another company’s servers, it could create another potential point of access for hackers, insiders, governments, or law enforcement.
Walsh describes that as a potential “side door” around end-to-end encryption rather than a technical break in the encryption itself. Authorities seeking information that Apple cannot provide from an end-to-end encrypted conversation could potentially seek a copy stored elsewhere, if one exists.
OpenAI’s description places important limits on that scenario. Installing the plugin does not upload an entire Messages history, and content accessed through it remains on the Mac by default, according to the company.
AI gets access to more than the chatbox
The Messages integration comes amid a broader expansion in the data and device capabilities AI services are seeking access to.
In research provided to Fortune, Lookout said its analysis of more than 420 million Android and iOS applications shows the permissions and capabilities of AI-related apps have continued to grow over the past year. The company also tracked increased access among iOS AI apps across eight categories of sensitive or high-risk capabilities.
“There has been a trend we’ve seen quite steadily over the past year where AI services are asking for access to more and more data,” Richardson said.
The Messages plugin uses existing macOS capabilities rather than a new iMessage API built by Apple specifically for ChatGPT, according to OpenAI. Its setup requires users to approve AppleScript, Accessibility, and Full Disk Access.
Fortune asked Apple whether it anticipated existing macOS permissions being used to give AI agents the ability to read and search Messages and whether it is considering additional safeguards as AI agents gain access to sensitive applications.
Apple did not immediately respond to Fortune’s request for comment.
Walsh said the risks created by third-party software accessing sensitive information aren’t unique to ChatGPT or AI. What is changing, he argues, is the amount of information AI can rapidly search and analyze once it has that access.
“I would never build an iMessage integration that has the ability to read messages ever,” Walsh said, “Because it breaks the fundamental protections that end-to-end encryption brings.”
As AI agents become more capable, much of their usefulness will come from gaining access to more of people’s digital lives—and the complication is that those lives overlap. With Apple Messages, one person can give an AI access to years of conversations that were written by plenty of people who never agreed to let it in.
This story was originally featured on Fortune.com
.png)
3 hours ago
2




English (US) ·