OpenAI just gave ChatGPT a way out of the chatbox and straight into your iMessage threads, and testing it turned into a small lesson in how AI tools can quietly reach further than you expect.
A newly released plugin lets the ChatGPT app for Mac search your Messages conversations, summarize what’s going on, and even draft and send replies. It’s drawing attention for good reason — and one tester’s experience showed how quickly the tool can step past its intended bounds.
What the ChatGPT Messages plugin does
The plugin is now live in the ChatGPT plugins directory, sitting in the Public section where you can find it by searching. Once installed, it gives the Mac app three core abilities: searching through your Messages history, summarizing your current conversations, and drafting replies that it can send either with your approval or, if you opt in, without it.
There’s nothing radically new about the concept. ChatGPT has offered a similar Gmail plugin for a while, one that can dig through your inbox and send messages on your behalf. If the idea of an AI reading and texting your contacts feels unsettling, that unease predates this release — it’s just now landed on Apple’s messaging platform.
One important caveat, especially for a Windows-focused site: the Messages plugin works only on the ChatGPT app for Mac. It does not work on Windows, and it doesn’t work on the mobile ChatGPT app either. It also can’t be reached remotely — the plugin runs directly on your Mac, which is what lets it read local conversations in the first place.

The permissions it demands
Getting the plugin up and running means granting it some pretty wide-ranging access. According to the tester, installing it requires letting ChatGPT send messages, read your contacts, and — the part that makes people pause — grant full disk access to your system.
That last permission is exactly what you’d want to think twice about. Full disk access gives an application the ability to read virtually everything on your Mac, and it’s a permission you should hand out sparingly. The tester went ahead and clicked Allow, noting that skepticism here is the healthy instinct.
When it comes to sending messages, ChatGPT has a default safety rail: it runs any draft past you before sending. There’s also an “Always allow sending to this chat” toggle, which OpenAI itself recommends leaving turned off unless you’re comfortable with the model firing off texts without a review step.
The moment it took over the screen
The tester’s run-through started normally. Prompted to describe recent conversations, ChatGPT summarized six chat threads — including family chats, a message from Verizon, and one from Roto-Rooter after a plumber visited a leaky drain. A test send to the tester’s wife went through smoothly after a “Send this to…” prompt was confirmed.
Things got interesting when the tester asked the plugin to delete spam. The Messages plugin can search and send, but it can’t delete messages. So rather than stop, ChatGPT found another route.
Suddenly, the interface filled with screenshots of the actual Messages app. The model took control of the Messages window, browsed through conversation threads on its own, located the spam, and used your Mac’s mouse pointer to click the Delete button — completing the request you’d made.

Why it happened
It’s worth being clear about what actually occurred here. ChatGPT didn’t break out of its sandbox or do anything you hadn’t authorized. Instead, it leaned on the “computer use” capabilities the tester had granted during a separate, earlier test — capabilities the tester had simply forgotten to rescind once that test wrapped up.
That distinction matters. The takeover wasn’t a rogue action or a flaw in the Messages plugin itself; it was the plugin piggybacking on a broader permission that was still active in the background. In other words, the tool did exactly what it had been given the power to do — it just did something you weren’t watching for.
What this means for you
The immediate consequences here were trivial — a few spam texts deleted. But the episode is a useful reminder of a broader risk with capable AI assistants: a small, seemingly harmless request can trigger a chain of actions you didn’t fully anticipate.
If you’re an experienced user who can get caught out by this, it’s worth pausing to consider how easily permissions can accumulate. Each test you run, each permission you grant, can linger in the background and resurface later in ways you didn’t expect.
How to get it (and what to do)
If you want to try the plugin, install it from the ChatGPT plugins directory on the Mac app, in the Public section. Keep in mind it’s Mac-only, so Windows and mobile users are out of luck for now.
Before you do, review the permissions carefully. If full disk access feels like too much, that’s a reasonable reason to hold off. And when you’re done testing any feature that grants broader control — like “computer use” — go back and rescind those permissions rather than leaving them running indefinitely.
Finally, leave the “Always allow sending to this chat” option off unless you have a specific reason to turn it on. A quick review before every send is a small price to pay for keeping the model from texting your contacts while you’re not looking.
Source: PCWorld
Over to you: Would you install a plugin that lets ChatGPT send your iMessages, or leave that power on the table?


