CampaignSMS

New ChatGPT Update Brings Apple Messages to Mac – SQ Magazine

Smarter Insights for a Fast-Moving Digital World
OpenAI added an Apple Messages plugin to the ChatGPT desktop app for macOS in release notes and its own plugin guide flags a known issue with tasks that disable approval prompts. The plugin reads, searches, and sends iMessage, SMS, and RCS chats.
The plugin gives the macOS app direct access to conversations in Apple’s Messages app, where ChatGPT can read, search, and prepare outgoing texts. OpenAI lists it as available on all plans in the ChatGPT desktop app for macOS, with support in both ChatGPT Work and Codex.
OpenAI has drawn two boundaries around it. The plugin does not let anyone drive ChatGPT remotely by texting it, and it does not function in ordinary ChatGPT chats.
Hardware narrows the audience further. OpenAI’s plugin documentation restricts the feature to Apple silicon Macs, which leaves Intel machines out.
Everyday conversations just got easier with the new Apple Messages plugin.

Search messages, catch up on conversations, draft and send replies—all with ChatGPT on your Mac.

Now available in ChatGPT Work and Codex on desktop. pic.twitter.com/nicfZMuxZc
OpenAI describes the send step as consent-gated. “By default, ChatGPT sends messages only after you approve the message and its recipients,” the company states in the release notes.
That default comes with an exception OpenAI documents itself. The plugin guide covers the risks of granting persistent approval, the steps for revoking access, and a known issue with tasks that disable approval prompts. A task configured that way removes the one control most users assume is always on, a sharper problem than the permission questions raised by ChatGPT’s advanced security mode.
The documentation confirms the issue and stops there, with no trigger, scope, or fix described. Nothing OpenAI has published says how many users already run tasks configured this way, whether a patch has shipped, or whether a message sent under a suppressed prompt gets flagged afterward.
Four questions sit unanswered in the release notes:
Anyone who has already granted the plugin persistent approval can revoke it through the steps in OpenAI’s plugin guide, then audit any tasks set up to skip prompts. Reviewing recently sent threads in Messages helps reduce the risk that an outgoing message went unnoticed, though it does not rule that out.
Codex picked up read-only thread sharing in the same update. A snapshot freezes a local Codex thread at the moment of creation and ignores later changes to the original, and OpenAI redacts known secret patterns before the link goes out. Links from personal accounts open for anyone holding the URL, while workspace links stay inside that workspace.
Redaction has a limit OpenAI states plainly: sensitive information can survive the pass, so snapshots need a read-through before sharing. That caution sits alongside the company’s earlier work on secret handling in Codex.
Sites gained collaborative editing where owners invite active members of the same workspace. Editors can update content and database data, save versions, and publish changes once the owner completes the first publication, while owners keep control of access, settings, analytics, and version restoration. Some Site owners can also change a ChatGPT-hosted URL without redeploying, and the old address redirects to the new one.
One weekly briefing with the launches, AI developments, and breaches that matter. No filler.
Access to a personal message archive changes both what an assistant can do and what it can spill. Reading and searching a Mac’s iMessage history makes ChatGPT useful for the retrieval people actually want, such as digging out an address someone texted months ago, and that same reach turns an unapproved send into something far costlier than a bad draft in a chat window. The approval prompt carries the entire safety model here, which is why a documented path to switching it off deserves more attention than any other line in the release notes.
What happens next depends on how quickly OpenAI closes the task issue and how loudly it tells affected users. Anyone turning the plugin on now should leave the default approval behavior alone and recheck the plugin’s permissions after setting up any task, because that is the documented route to a send without a prompt. OpenAI named the problem in its own documentation, which sets the bar for how visibly it now has to close it, and its usage numbers put a large audience one toggle away from the answer.
This article has been reviewed and fact-checked by Robert A. Lee. SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.
Founder & Senior Journalist
Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.




Table of Contents
Smarter Insights for a Fast-Moving Digital World
Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.
We respect your time. One high-signal briefing a week: tech, AI, and security. Nothing else.
We track tech, AI, and security 24/7. You get a 5-minute weekly summary.

source

Leave a Reply

Your email address will not be published. Required fields are marked *