Security

ChatGPT's iMessage Plugin Reads Your Contacts' Messages Without Their Consent

OpenAI's new Mac integration lets AI search years of message history, raising questions about one-sided privacy decisions in everyday conversations.

Omega Editorial· August 31, 2026· 4 min read

A new ChatGPT plugin for Mac can search a user's Apple Messages directly, summarize group chats, and draft replies by pulling context from months-old conversations. The feature requires explicit permission from the person installing it. Everyone else in those conversations gets no notification and no choice.

According to reporting first published in The Jerusalem Post, the integration creates a fundamental asymmetry: one participant decides to grant AI access to an entire conversation history, while everyone else on the other end remains unaware a third party is reading their words.

Why it matters

This isn't about a single product. It's about a pattern that's already widespread and accelerating. As AI assistants become standard productivity tools, millions of people are unilaterally deciding to make private conversations searchable and machine-readable—without the knowledge or consent of the people they're talking to. That creates new liability questions, erodes assumptions about message privacy, and fundamentally changes what it means to have a conversation.

How the plugin works

OpenAI has stated the plugin reads messages only when a user's request specifically calls for it, doesn't build a standing index of message history, and stores conversations locally on the Mac by default rather than uploading them to a server. These are meaningful technical guardrails.

But they don't address the core issue. The decision to let an AI read a conversation was made by one person, on behalf of everyone in it. A security researcher noted that every person messaged through iMessage will never know a third party is inside that application.

Some have pushed back on characterizing the feature as surveillance, noting it's off by default and requires explicit consent. Even those more measured critics acknowledge the underlying risk: once a message is decrypted and readable on someone's device, another piece of software reading it from there has effectively routed around the protection encryption was supposed to provide.

Scale changes everything

People have been screenshotting texts and pasting them into ChatGPT for years. What's different now is scale and searchability. A screenshot is one message, deliberately chosen. A standing AI integration with access to years of message history is a capability that can reach back through an entire relationship's written record the moment anyone asks it to.

As one privacy-focused technology company pointed out, the exposure isn't limited to people who use ChatGPT themselves. Someone who has never opened the app or accepted any terms of service can still have years of private conversations become searchable because the person on the other end decided it was convenient.

Unanswered questions

The consent problem has no clean solution under existing privacy frameworks. A text message is data about two people, or more in a group thread. There's no mechanism today for the other party's consent to enter the picture.

Liability is equally murky. If an AI-drafted reply built partly from a misread old message causes real harm—professionally, financially, or personally—whose responsibility is it? The person who hit send, or the company whose model generated the draft?

And there's a deeper question: if both sides of a conversation are using AI to draft and summarize messages, is it still a conversation between two people, or is it AI corresponding with AI while two humans skim the output?

Practical steps

Organizations should establish clear policies about whether client communications, HR conversations, or anything under legal privilege can pass through an AI assistant at all. Individuals should treat any AI-messaging integration as a decision made on behalf of everyone they talk to, and keep genuinely sensitive conversations on channels they control end to end.

The executive who forwards 15 message threads to an AI assistant each morning isn't doing anything malicious or unusual. But he's deciding on behalf of 15 other people who never got a vote. Multiply that by however many of those 15 made the same decision back, and the honest picture isn't two people staying in touch—it's an arrangement none of them designed and none were quite asked to join.

These details were first reported by The Jerusalem Post.

#chatgpt#privacy#imessage#ai ethics#consent#enterprise ai

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 4 min read

AI Cyberattacks Exploit the Authorization Gap in Corporate Defense

Autonomous AI defense tools can contain breaches in seconds, but most companies haven't authorized them to act without human approval.

Via AI Watch · Aug 31, 2026
Security· 3 min read

ATM Encryption Flaws Expose Software Supply Chain Risks

Nine vulnerabilities in widely deployed disk encryption software highlight the challenge of patching security holes across multiple industries.

Via WIRED · Aug 31, 2026
Security· 5 min read

AI-Powered Cyberattacks Now Move Faster Than Human Defenders

Over 100 tech companies warn that autonomous AI agents can exploit vulnerabilities in minutes while traditional security operations take hours to respond.

Via AI Watch · Aug 30, 2026