US National WireUS NATIONAL WIRE
TechOpinion

The Open Door: OpenAI's iMessage Plugin is a Security Nightmare

Portrait of Dana Kessler
Dana Kesslercybersecurity & privacyAug 21AI
The Open Door: OpenAI's iMessage Plugin is a Security Nightmare

AI-generated image · US National Wire

By granting Full Disk Access and contact permissions, users aren't just automating their inbox—they are dismantling their device's perimeter.

In the world of cybersecurity, we talk about the 'attack surface'—the sum of all points where an unauthorized user can enter or extract data from a system. Usually, the goal is to shrink that surface. With OpenAI's new Apple Messages plugin, we are seeing the opposite: a catastrophic expansion.

According to reporting from Engadget and TechCrunch, OpenAI has released a plugin for the Apple Messages app on Mac, currently available to Codex and ChatGPT Work users. On the surface, it is marketed as a productivity boon. TechCrunch reports that the tool allows users to search for buried information, analyze conversations, and even have the AI draft and send replies or delete messages on their behalf.

But look at the permissions required to make this 'feature' work. As Engadget notes, this isn't a simple API handshake. To enable the plugin, users must grant ChatGPT access to their on-device Messages history and—most alarmingly—change their Mac's System Settings to provide 'Full Disk Access.' Additionally, users must hand over access to their contact names and automation tools.

From a defender's mindset, 'Full Disk Access' is the nuclear option of permissions. It effectively removes the barriers between the application and the core of the operating system. While OpenAI told Bloomberg that the plugin runs locally and does not create a message index, the technical reality of granting an AI agent the ability to read, write, and delete files across a disk is a massive risk.

Furthermore, the human element is a glaring vulnerability. TechCrunch reports that OpenAI warns users against turning on 'persistent approval,' as doing so removes the final human review before the AI sends a message. If a user opts into that automation, they are essentially handing the keys to their digital identity to a black-box model.

There is also the matter of corporate instability. Engadget reports that Apple and OpenAI are currently embroiled in a legal battle; Apple sued OpenAI in July, alleging trade secret theft and claiming the AI lab hired Apple employees specifically to obtain confidential information. This is not a partnership of trust. In fact, Engadget points out Apple's history of aggressively blocking third-party iMessage access, such as the 2024 crackdown on the Beeper Mini app.

OpenAI may frame this as a convenience, but for anyone who values privacy, it is a remote-access vector disguised as a plugin. When you give an LLM the power to read your most private conversations and the system-level permission to act on them, you aren't optimizing your workflow—you're compromising your machine.

Sources

More from Dana Kessler