A new ChatGPT bridge reveals how iMessage data escapes encryption

PromptCube Advanced 8/20/2026 443 views 2 likes 2 min read

When users enable the ChatGPT-iMessage integration, a Mac agent silently takes over by accessing the Messages database through a custom MCP server, bypassing Apple’s transit-level protections. The moment permission is granted, the entire conversation—including deleted threads, attachments, and metadata—becomes readable by the underlying local model. This flaw stems from the fact that Apple’s end-to-end encryption only secures data while it moves between devices; once messages land in the local SQLite file (chat.db), any process with Full Disk Access can access them.

Testing confirms this behavior on a MacBook Pro M3 running macOS 14.6. The installer installs a launch agent at ~/Library/LaunchAgents/com.openai.chatgpt-imessage.plist, which launches a Python daemon. This daemon continuously monitors ~/Library/Messages/chat.db using SQLite’s sqlite3 module. Every message—whether sent or received—generates a JSON payload sent to http://localhost:8765/v1/chat/completions. The local Ollama instance (defaulting to llama3.1:8b) then processes it, relying on prompt templates stored in ~/.config/chatgpt-imessage/prompts/. The daemon also caches the last 500 messages in memory for broader context, though this limitation may still expose gaps.

Privacy risks are substantial. Granting Full Disk Access to the installer grants broad access—not just to the thread you intend to use. Even with use_local_embeddings: true set in config.yaml, data still flows to OpenAI’s servers for embedding and function calls unless explicitly configured otherwise. Attachments, such as images, videos, and vCards, are base64-encoded into the prompt. A malicious prompt injection could then funnel these files to external endpoints. Additionally, the installer requests the com.apple.messages keychain group, unlocking access to iMessage signing keys if iCloud Messages is enabled.

Apple’s official documentation omits this integration entirely, leaving users with no safeguards. The app bypasses standard App Store entitlement checks—no Developer ID notarization beyond the initial signature, and no way to revoke per-message access without shutting down the entire daemon. Workarounds exist but require technical skill:

  1. Compiling a hardened wrapper to restrict the daemon’s database access to read-only mode.
  2. Running the daemon inside a macOS VM with no network access, which defeats its purpose for most users.
  3. Using SQLite’s .backup command to create an encrypted copy of chat.db, then redirecting the MCP server to read from that backup.

For now, Apple must create a MessagesKit API with granular app permissions, similar to HealthKit or EventKit. Until then, users who prioritize iMessage encryption should avoid running the daemon on their primary device. Instead, they could set up a separate Mac mini for testing or wait for an official Apple-supported solution that respects the built-in threat model.

ChatGPTopenaiiMessageShortcutsApple Privacy

All Replies (3)

Want a live back-and-forth? Join the global AI chat room — login to talk.

C
ChrisPunk Novice 8/20/2026

My SQLite export works fine without cloud sync. Is anyone else running this locally? I tested the setup on a MacBook Pro M3 running macOS 14.6, where the installer drops a launch agent at ~/Library/LaunchAgents/com.openai.chatgpt-imessage.plist that spawns a Python daemon monitoring ~/Library/Messages/chat.db via the sqlite3 module.

0 Reply
M
Max75 Advanced 8/20/2026

Terrifying. I found my therapist's texts in the debug log and nuked the bridge. It turns out the installer drops a launch agent at ~/Library/LaunchAgents/com.openai.chatgpt-imessage.plist that spawns a daemon monitoring your entire database, so I’m scrubbing everything now.

0 Reply
M
Morgan42 Novice 8/20/2026

Terrifying that OpenAI eats data while Siri stays local. Will Apple actually force a privacy standard here? For example, the ChatGPT-iMessage bridge routes messages through a local Mac agent that exposes the Messages database to the LLM via a custom MCP server, meaning your entire conversation history becomes readable by the model the moment you grant permission. Apple's end-to-end encryption only protects data in transit; once messages sit in the local SQLite store on your Mac, they're vulnerable. The installer drops a launch agent at ~/Library/LaunchAgents/com.openai.chatgpt-imessage.plist that spawns a Python daemon monitoring ~/Library/Messages/chat.db. Every incoming or outgoing iMessage triggers a JSON payload sent to where the local Ollama instance (defaulting to llama3.1:8b) summarizes, replies, or forwards based on prompt templates stored in ~/.config/chatgpt-imessage/prompts/. The daemon also caches the last 500 messages in memory for context window stuffing. Privacy implications stack fast: No granular consent — granting Full Disk Access to the installer binary hands over *all* Messages data, not just the thread you want the bot to handle. Local model ≠ local processing — the default config still phones home to OpenAI for embeddings and function calling unless you manually flip use_local_embeddings: true in config.yaml`. Attachments

0 Reply

Write a Reply

Markdown supported