OpenAI has quietly turned ChatGPT into something that can read your text messages. A new plugin for the ChatGPT desktop app on Mac lets the assistant search your Messages history, summarize what you missed, and even write and send replies on your behalf. It works across iMessage, regular text messages, and RCS chats, and it lives inside two parts of the ChatGPT app called Work and Codex, which handle everyday research and writing tasks and coding work.
Getting this running is not a one-click affair. You have to approve ChatGPT's access to your on-device message history, then separately go into your Mac's privacy settings and hand the app what's called Full Disk Access, which means it can technically see far more than just your texts. On top of that, you also have to approve access to your contacts and to the automation tools that let apps act on your behalf.
None of that happens by accident, and OpenAI says the processing happens on your own machine rather than uploading a full copy of your conversations. That does not remove every risk, though. Giving any app the power to read your messages and act on them opens a door for someone to send you a text with hidden wording designed to trick the assistant into doing something you never asked for.
OpenAI's own documentation already warns users to keep manual approval turned on for conversations that might contain instructions meant to fool the AI. That tells you the company already sees this as a real problem, not a hypothetical one. It also tells you this kind of trick, often called a prompt injection, is becoming a standard risk wherever AI assistants get access to outside messages.
The bigger story here is the relationship between OpenAI and Apple, which has gotten worse, not better. Apple is currently suing OpenAI in federal court, accusing it of stealing trade secrets to help build its own hardware products, a case tied to OpenAI's purchase of Jony Ive's device startup for several billion dollars. The two companies also worked together last year to bring ChatGPT into Siri, so this partnership is fraying at the same time OpenAI is building features that sit deep inside Apple's software.
Apple has not been shy about cutting off apps that connect to iMessage without permission. It previously blocked Beeper Mini, an app that let Android phones send and receive iMessages, and kept blocking it even after the company tried to patch around the shutdown. Whether Apple tolerates a ChatGPT plugin doing something similar is worth watching.
For any business running a fleet of Macs, the real point is that AI assistants are quietly gaining the kind of system level access once reserved for antivirus or IT management software. OpenAI does offer managed settings that let IT teams control or block this access on company devices. Any operator issuing Macs to staff should know that setting exists before employees turn this on themselves.