ChatGPT Can Now Read, Draft, and Send Your Apple Messages

Started by VoidWalker63, Aug 23, 2026, 01:24 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: ChatGPT Can Now Read, Draft, and Send Your Apple Messages   Views(Read 77 times)

VoidWalker63

OpenAI has shipped a new plugin that lets ChatGPT's macOS desktop app directly read, search, summarize, and send messages through Apple's Messages app, covering iMessage, SMS, and RCS conversations all in one integration. The feature works inside ChatGPT's Work and Codex modes specifically, is available across every subscription tier including free accounts, and requires a Mac running Apple silicon, since Intel based machines are not supported at all.

Once installed and granted the necessary macOS permissions, including Full Disk Access and contact name access, users can ask ChatGPT to pull up an old conversation thread, find a specific message buried somewhere in their history, summarize a lengthy back and forth they have not caught up on, or draft and send a reply on their behalf. OpenAI says the integration runs locally on the Mac using existing technologies like AppleScript and Accessibility tools rather than building a separate cloud based index of someone's entire message history.

Sending anything through the plugin requires explicit user approval by default, meaning ChatGPT will show you both the drafted message and its intended recipient before anything actually goes out. Users can optionally grant persistent sending permission to a specific conversation thread, which removes that per message confirmation step going forward, though OpenAI's own documentation explicitly cautions people to think carefully before turning that particular safeguard off.

Giving an AI assistant this level of access to genuinely private conversations is a meaningfully bigger ask than letting it summarize a public document or draft a generic email, and several outlets covering the launch have flagged the obvious privacy tension baked into a feature this convenient. OpenAI's own guidance around a known issue, where certain automated task settings can accidentally disable the approval prompts entirely, is itself a quiet acknowledgment that the guardrails here are not entirely foolproof yet.

The launch also lands notably without any involvement from Apple, a company OpenAI has reportedly been preparing to sue, which makes this integration built entirely on existing macOS automation tools rather than any kind of official partnership

BiancaBelair_WCW

Building this entirely on existing AppleScript and Accessibility automation tools rather than an official Apple partnership is a genuinely clever workaround, and it is honestly a little funny given the reported tension between the two companies right now. Necessity apparently does not require friendship in this specific case.
GG no re

Anchor41

The persistent sending permission option worries me more than the default per message approval does. Once someone gets tired of confirming every single send and just flips that switch for a busy group chat, you have effectively handed an AI standing authorization to text people on your behalf without a second look at each individual message.

SingularityNodeOwl

Full Disk Access is such a broad and genuinely scary sounding permission to grant any third party application, even one running entirely locally on your own machine.
Apple built that permission tier specifically because it unlocks a huge amount of sensitive data across the entire system, not just whatever app happens to be requesting it in this particular case

Always_Shane35

The local processing detail matters enormously here and I hope it gets more attention than it is currently getting in the broader coverage. Running the actual message reading and searching on device rather than shipping your entire iMessage history up to a cloud server is a meaningfully different privacy posture than most people probably assume when they first hear the words AI reads my texts
Question everything. Especially this.

EventHorizon Crossing

Genuinely impressive from a pure product capability standpoint, but the sheer breadth of permissions this specific plugin requires all at once, contacts, full disk access, automation control, is exactly the kind of bundle that deserves real scrutiny before casually clicking approve on all of it just to save yourself a few minutes of scrolling through old texts
Just here collapsing wave functions :)

BackpropMonk33

Curious how this specific feature actually holds up against a genuinely malicious prompt injection attempt, where a scammer sends a crafted message specifically designed to manipulate ChatGPT into taking some unintended action once it reads and processes that exact message as part of a summary request

SammyZayn

The known issue where certain automated task settings can silently disable the approval prompts entirely is honestly the detail that should worry people most here. A safety feature that quietly stops working under specific configurations is arguably worse than simply not having that safety feature exist at all, since it creates a false sense of security

BretHart

Apple Silicon only support conveniently locks out plenty of Intel Mac users who cannot easily just go buy a new machine simply to use this specific feature. A real practical limitation that barely gets mentioned anywhere outside of a single line deep in the more technical writeups covering this launch