ChatGPT’s New Mac Messages Plugin Can Read and Send iMessages, Raising Privacy Questions
OpenAI has introduced a new Messages plugin for the ChatGPT desktop app on macOS that can interact directly with Apple’s Messages application. The feature has already raised questions about privacy...
OpenAI has introduced a new Messages plugin for the ChatGPT desktop app on macOS that can interact directly with Apple’s Messages application. The feature has already raised questions about privacy and security because it gives ChatGPT the ability to read, search, summarise, write and send iMessages on a user’s behalf.
The feature was highlighted by Bloomberg’s Mark Gurman and works through existing macOS automation capabilities rather than bypassing Apple’s security protections.
Users must grant extensive permissions
The plugin does not silently gain access to Messages. Users must go through a series of permission prompts before it can operate.
ChatGPT can request access to the Messages database stored on the Mac, while users may also need to enable Full Disk Access, contacts access and automation permissions through macOS settings.
The feature is also not active during every ChatGPT conversation. It works when users deliberately launch the ChatGPT Chat Bar or begin a ChatGPT Work or Codex session. Standard ChatGPT conversations do not automatically receive access to Messages.
That distinction is important, but the permissions required still give the feature access to highly sensitive personal communications.
Apple’s history with iMessage makes this unusual
The development is particularly interesting because Apple has traditionally maintained tight control over iMessage and has aggressively blocked third-party attempts to interact with its messaging infrastructure.
Beeper Mini became a prominent example in 2023. The Android application attempted to provide iMessage functionality outside Apple’s ecosystem and was repeatedly blocked by Apple before eventually being discontinued.
Apple had argued that Beeper Mini had reverse-engineered parts of the iMessage system and raised concerns about credentials, metadata and potential security risks.
The ChatGPT plugin takes a very different approach. Rather than attempting to break into iMessage or recreate Apple’s messaging protocol, it uses macOS’s own automation and accessibility capabilities with explicit user permissions.
Has Apple approved the integration?
One major question remains unanswered: whether Apple and OpenAI worked together on the feature.
Apple has not publicly confirmed a partnership surrounding the Messages plugin, and the company has reportedly not provided a response regarding the new functionality.
The timing is also notable because Apple and OpenAI are already involved in a separate legal dispute. Apple has accused OpenAI of misappropriating trade secrets as the AI company explores future hardware and software products.
Convenience versus privacy
For users, the feature could be useful. ChatGPT could potentially find information buried inside old conversations, summarise lengthy message threads or draft and send replies without requiring users to manually switch between applications.
But the same capabilities create a difficult privacy question.
Messages often contain personal conversations, photographs, contact information, financial details and other sensitive information. Giving an AI assistant access to that data, even with explicit permission, represents a significant expansion of what the assistant can see and do on a personal computer.
The issue is therefore less about whether ChatGPT is bypassing Apple’s security and more about how much access users are willing to grant an AI system.
As AI assistants become increasingly integrated with operating systems, the boundary between an assistant that answers questions and one that can actively interact with a user’s private digital life is becoming much harder to define.




