Is the Mac's Security Promise Broken? OpenAI Hires Ex-Apple Developers to Create Plugin That Reads and Sends iMessages

Deep News
2 hours ago

The relationship between Apple and OpenAI has become increasingly delicate. Last month, Apple filed a federal lawsuit against OpenAI, accusing the company of systematically stealing its trade secrets "at every level." However, last Friday, OpenAI countered by releasing a plugin that enables ChatGPT to read, search, draft, and send users' iMessage, SMS, and RCS messages. As netizens put it, this seemingly simple operation poses a significant challenge to Apple's security framework, raising the question: "Is the MacBook no longer secure?"

What makes this particularly awkward for Apple is that the plugin bypasses none of the security defenses Apple prides itself on. OpenAI used only the keys Apple itself created: Full Disk Access and Accessibility permissions. Adding to the drama, the OpenAI executive who built this plugin is the very person who previously created Shortcuts at Apple.

One Plugin, Three Keys

So what exactly did OpenAI create? It's a macOS plugin installed from the ChatGPT plugin interface, available only in the ChatGPT Work and Codex interfaces—not in the standard ChatGPT conversation window, web version, or mobile app. It's important to note that this plugin runs exclusively on Apple Silicon Macs and does not support older Intel-based models. Once installed, it can search message history, summarize conversations, draft and send replies by contact name, identify spam messages for deletion, and extract birthdays from chat logs to add to the calendar. It covers iMessage, SMS, and RCS protocols—meaning messages from Android users are also within its scope. All ChatGPT plans, including the free tier, can use it.

To make the plugin function, users must grant three permissions: Full Disk Access, contact name access, and automation permission. The first is the most critical. Full Disk Access is not just a "message permission"; it's a master switch in macOS that, once granted, allows the app to read all protected areas of the disk. Users might think they're only approving ChatGPT to read a few conversations for a summary, but in reality, they're approving the AI to read their entire data archive, including emails, Safari browsing history, and Time Machine backups. OpenAI explains that the plugin operates locally, does not index all user messages, and requires explicit authorization for everything. Additionally, when the AI sends messages on behalf of the user, it defaults to requiring confirmation for each one, but users can enable "persistent authorization" to skip this step entirely. Furthermore, if users set up scheduled tasks, the per-message confirmation is bypassed. In such cases, ChatGPT can send texts in your name without your approval.

iPhone Remains Fortified

It must be emphasized that this plugin only runs on macOS and cannot be implemented on the iPhone. iOS's sandbox mechanism was designed from day one to prevent apps from reading each other's data, and the iPhone has no AppleScript at all. However, the Mac's ecosystem walls are different. The Mac has a history spanning decades, long predating the concept of a "walled garden"; AppleScript was born in 1993, a full fifteen years before the App Store. These mechanisms serve screen readers, enterprise automation processes, and thirty years of accumulated Mac software ecosystem. As a result, Apple cannot disable any of these features individually without destroying everything else.

Because the plugin uses standard system permissions, the technical controls Apple typically imposes between apps and data—sandboxing, data processing rules, and review—do not apply here. In other words, any third-party Mac developer could create the same thing, as long as users grant authorization, without Apple's knowledge, participation, or approval. This isn't the first time Apple has faced such a situation. In 2024, the third-party app Beeper Mini allowed Android users to access iMessage, and Apple's response was to repeatedly cut off its access until Beeper gave up. But that time, Apple was severing connections on its own servers; this time, OpenAI is using permissions on users' own computers that Apple itself opened up.

The Plugin Creator Comes from Apple

The most dramatic part of this event is that the person who built this plugin for OpenAI is someone they recruited from Apple. The OpenAI employee who announced this feature on X is Ari Weinstein. Years ago, he and Conrad Kramer, in their twenties, created the iOS automation app Workflow, which was acquired by Apple in 2017, and the two subsequently joined the company. Workflow later evolved into the Shortcuts we know today, pre-installed on every iPhone, and further developed into Apple's system-level functional interaction open framework, App Intents. App Intents is precisely the technical foundation for Apple's new-generation Siri.

In 2023, they co-founded Software Applications with another Apple veteran, Kim Beverett, to develop native desktop interaction and screen workflow tools, including the well-received macOS screen recording tool Screen Studio and a Mac-native AI assistant named Sky. Beverett also worked at Apple for nearly a decade, overseeing Safari, WebKit, privacy, Messages, Mail, and FaceTime—exactly the areas this plugin now touches. In October 2025, OpenAI acquired this company, bringing the entire 12-person team on board. The specific financial terms were not disclosed, but OpenAI gained a group of senior developers with the deepest understanding of Apple's systems. The recently released iMessage plugin is a continuation of Sky technology within ChatGPT; the "computer use" feature OpenAI previously launched in Codex also came from this team.

In other words, OpenAI recruited a team of architects who built Apple's automation frameworks, and now they're using the mechanisms they wrote themselves to open up Apple's system from the outside. They even know these doors better than Apple does, because they were the ones who built them. According to Apple's lawsuit documents, OpenAI has now recruited over 400 former Apple employees.

Fighting in Court While Advancing AI

The relationship between Apple and OpenAI is in a highly dramatic state: Apple is simultaneously accusing OpenAI of stealing its trade secrets while also advancing its cooperation with the company. Of course, Apple is also partnering with other AI vendors like Google to reduce its reliance on OpenAI. On July 10, Apple filed a 41-page complaint in the U.S. District Court for the Northern District of California, naming OpenAI Foundation, OpenAI Group PBC, hardware subsidiary io Products, and two former Apple employees as defendants. These include OpenAI's Chief Hardware Officer Tang Yew Tan, who worked at Apple for 24 years and served as Vice President of iPhone and Apple Watch Product Design, and engineer Chang Liu, who spent eight years as a senior systems electrical engineer at Apple before leaving earlier this year. Apple alleges that Tan used internal Apple project code names to extract information during OpenAI's recruitment process, required candidates to bring actual components like batteries and logic boards to interviews for "demonstrations," and circulated a document about Apple's departure process to teach new employees how to circumvent Apple's exit security checks. Liu is accused of failing to return an Apple-issued laptop after leaving and using it to download confidential technical documents.

OpenAI has strongly denied these allegations. On August 4, OpenAI published a lengthy blog post responding point by point with email evidence, noting that Apple's claim of "sending a letter to OpenAI in February without receiving a reply" is problematic, because Apple's external lawyers confused two Asian surnames and sent it to the wrong recipient—there was no unanswered communication at all, and it was OpenAI that pointed out this error. OpenAI also refuted Apple's assertion of communication with OpenAI's General Counsel as untrue. Consequently, OpenAI filed a 31-page motion to dismiss, calling Apple's complaint "fundamentally flawed from the start." The preliminary injunction hearing is scheduled for October 1.

However, the lawsuit does not affect the companies' cooperation, and Apple does not appear inclined to terminate the partnership. ChatGPT remains integrated in Siri to this day, and Apple specifically stated in its complaint that the integration cooperation agreement between the two parties is not within the scope of this case. In other words, Apple is simultaneously angrily suing OpenAI while calmly continuing their collaboration.

AI Features Delayed for Two Years

That said, Apple has indeed changed its AI partners and has not bound itself exclusively to OpenAI. Many may recall that at WWDC in June 2024, Apple demonstrated an AI-powered Siri capable of understanding personal context and retrieving information across apps. But that was a façade; Apple had not actually prepared the product for delivery, and what followed was a long series of delays. It wasn't until March 2025 that Apple was forced to announce postponement, which subsequently triggered consumer class-action lawsuits and shareholder securities fraud litigation. Consumers who bought new iPhones expecting these AI features felt deceived. One class-action lawsuit was settled in May with Apple paying $250 million. Mid-year, Apple finally released a revamped Siri, but the version that can truly search your messages and personal content, as originally showcased, is not expected until fall of this year—if there are no further delays.

Moreover, Apple's new Siri already uses Google's Gemini, not OpenAI's models, because in January, Apple shifted its Apple Intelligence partnership to Google. The entire situation is deeply embarrassing for Apple: two years ago, it announced a partnership with OpenAI to let AI read your messages, find context, and draft replies; but after two years, Apple still hasn't delivered, and OpenAI has gone ahead and produced the product, running on Apple's hardware. Meanwhile, Apple's own version will take a few more months and be powered by Google.

How Can Apple Respond?

Intriguingly, Apple has remained silent so far regarding this OpenAI macOS plugin, perhaps deliberating on its next steps. So what options does Apple have? Tightening permissions is the most likely move. Apple could refine Accessibility and Automation permissions in future macOS updates—for instance, adding mandatory system-level secondary confirmation for actions like "cross-app reading of communication records," or isolating the Messages database from Full Disk Access coverage and creating a separate dedicated authorization. This could strip the OpenAI plugin of its access. Given the current situation, Apple is unlikely to revoke the developer certificate outright. ChatGPT's Mac client is not in the Mac App Store, so Apple has no "review and removal" path available. However, Apple could theoretically revoke OpenAI's Developer ID certificate, rendering the app unable to launch on any Mac worldwide. Yet, such a move would signal a complete breakdown in relations and make continued cooperation difficult, so Apple would not resort to it lightly.

The most long-term strategy would be to build an exclusive moat with App Intents. The App Intents interfaces Apple opens to third-party developers are strictly limited, with true deep system operations held firmly by Apple's own underlying architecture. Thus, Apple could tighten legacy channels like AppleScript under the guise of "security and compliance" while ensuring its own Siri retains equal or even greater capabilities, pushing third parties into that restricted official interface.

Regardless of how Apple responds to this OpenAI macOS plugin, it must confront an awkward reality: Apple's celebrated security and privacy are facing increasing tests and challenges in the AI era. "Privacy is a fundamental human right"—a slogan Apple has used for a decade—is about to face a genuine stress test: third-party AI companies can read all of a user's message archives on a Mac, while Apple, as the platform provider, can neither control nor even know about it. Moreover, for consumers to have AI do more, they must give AI access to more personal data. This is itself a contradiction.

Since January, users have been able to share their Apple Health data with ChatGPT in exchange for medical advice; on that same day, ChatGPT's health features began testing in the U.S. and officially launched in July. Perhaps many consumers want their Apple devices to have AI capabilities—to read messages, remind them of important matters, reply to simple queries, and filter out useless information. This was the beautiful use case Apple showcased at WWDC 2024, but Apple delayed it for two full years without delivering. It's no wonder OpenAI stepped in first, hiring Apple's own people to build this product—though it could only be implemented on macOS. As of this writing, Apple has provided no official response or comment to any media outlet. That silence, in itself, may reflect Apple's lack of core technology in the AI era.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10