Your iMessage Privacy Was Just Sold by Someone Else’s ChatGPT—and Nobody Bothered to Ask You

(SeaPRwire) –   By: Oliver Hawthorne

The most dangerous sentence in the new ChatGPT Apple Messages plugin isn’t in the code. It’s not in the permissions dialog either. It’s this: “Everyone else in those conversations does not.” That’s the gaping hole in OpenAI’s latest roll-out. One Mac user installs a plugin, clicks “allow,” and suddenly an AI has the ability to read through years of group chats, private threads, and sensitive exchanges that were never meant for its eyes. The person who gave permission isn’t the only one whose data is now exposed. Everyone they’ve ever texted is now a silent, non-consenting participant in OpenAI’s experiment. Security expert Paul Walsh didn’t mince words when he called this “one of the most dangerous things I have seen in technology.” He’s not overreacting. He’s understating it.

Let’s be precise about what this plugin actually does. OpenAI rolled it out last week for ChatGPT on Mac. It lets the chatbot search iMessage, SMS, and RCS conversations, summarize group threads, draft replies, and even send messages. To make that work, the user must grant ChatGPT some serious macOS permissions: AppleScript, Accessibility, and Full Disk Access. That last one is the crown jewel. It’s the permission that allows software to read almost anything on your machine. OpenAI says the plugin runs locally by default, that it won’t read Messages unless explicitly asked, and that it doesn’t index your history just because it’s installed. That’s technically true. But it’s also beside the point.

The core issue here is consent. Or rather, the complete lack of it. When Paul Walsh describes this as functioning like spyware, he’s pointing at a fundamental asymmetry. Spyware typically operates without the user’s knowledge. This plugin operates with one user’s knowledge and zero regard for everyone else’s. The person who installs it has knowingly granted access. But the friends, family members, colleagues, and contacts who appear in those message threads never signed up for this. They never agreed to have their words summarized by an AI, searched by an algorithm, or potentially stored on a third-party server. Walsh’s point about trust is crucial here. Screenshotting a conversation and sharing it is a betrayal of trust, yes. But this is worse. This is letting a third party inside the conversation entirely, invisible to everyone but the one who opened the door.

The encryption argument is where this gets genuinely murky. Apple’s end-to-end encryption is still intact. The mathematics haven’t been broken. But encryption only protects data in transit, from one device to another. Once a message lands on the recipient’s Mac, it’s decrypted, readable, and vulnerable. The plugin operates after decryption. It reads messages on the device itself. So the protection that Apple built is effectively neutralized. The message is encrypted while traveling, then handed over to a third-party AI once it arrives. Lookout’s CTO Dave Richardson confirmed this, noting that enabling the integration introduces “significant risk” to what was historically a secure channel. He pushed back on the spyware label, arguing the feature is off by default and requires explicit user action. Fair enough. But the risk to non-users remains unchanged.

Privacy-focused firm Proton raised a parallel concern in its analysis this week. Their point cuts to the heart of the matter: the privacy implications extend to people who never touch ChatGPT. If you communicate with someone who uses this plugin, your messages are now within the reach of an AI system you never agreed to interact with. Proton also flagged the Full Disk Access requirement as a broader security consideration. That permission essentially opens the entire filesystem to ChatGPT, not just Messages. The potential for collateral exposure is enormous.

OpenAI’s defense is that message content stays local by default, only being uploaded if the user opts into cloud storage for those conversations. That’s a meaningful limit. But it’s also a conditional one. If a user decides to store a ChatGPT conversation in the cloud, the Messages content included in it follows standard retention policies. It can stay there until manually deleted. It can even inform the Memories feature, which persists across sessions. So the risk isn’t theoretical. It’s a matter of user choice, and users make bad choices all the time.

Walsh’s most pointed warning deserves attention here. He argues that storing encrypted conversation content on another company’s servers creates a “side door” around end-to-end encryption. Not a technical break, but a practical one. If law enforcement, hackers, or insiders can’t get the data from Apple because it’s encrypted, they can simply go to OpenAI instead. A copy might exist there, outside the protection of Apple’s encryption architecture. That’s not paranoia. That’s threat modeling.

The broader trend here is alarming. AI agents are increasingly demanding access to sensitive data, not just in chatbots but across operating systems. Lookout’s research on more than 420 million apps shows AI-related applications are seeking ever-expanding permissions. The trajectory is clear. Each new integration pushes further into personal data territory. Each new feature normalizes another layer of surveillance. The question is no longer whether AI can access your private communications. It can. The question is whether anyone is going to stop it.

We’re at an inflection point. The industry is racing to embed AI into every corner of digital life, often sacrificing user autonomy in the process. The ChatGPT Messages plugin is a perfect case study. It’s technically impressive, practically convenient, and fundamentally flawed. The people who most need to be aware of its implications are the ones who will never be asked for permission.

Author bio: Oliver Hawthorne is a Principal Correspondent permanently stationed at an international technology review, specializing in AI policy, data privacy, and the intersection of software and civil liberties.