OpenAI just gave ChatGPT access to your private text messages, and Apple, a company that once shut down a third-party iMessage app repeatedly until it stopped trying, has stayed completely silent. That silence is the most interesting part of this story.
As reported by Engadget, OpenAI has released a plugin that lets ChatGPT read, search, draft, and send replies through Apple Messages on Mac. Right now it is limited to ChatGPT Work and Codex users, but the capability is real and it is live. The demo OpenAI shared shows a user asking ChatGPT to surface conversations they missed the previous day, then using the chatbot to write and send a reply, all without opening Messages directly.
This matters because iMessage is not just an SMS app. It carries end-to-end encrypted conversations between Apple users, and it has always been a walled garden that Apple defends aggressively. In 2024, Apple repeatedly killed Beeper Mini’s access to iMessage until the company gave up entirely. So either OpenAI coordinated with Apple to build this, or it found a technical workaround Apple hasn’t moved to block yet. Neither explanation is entirely comfortable.
The setup process is deliberately involved, which is worth acknowledging. Users must grant ChatGPT several layers of permission:
- Allow ChatGPT access to on-device Messages history during setup
- Enable Full Disk Access in Mac’s System Settings
- Grant access to contacts
- Allow access to automation tools
So this is not something anyone installs by accident. But opt-in does not mean risk-free. Full Disk Access is one of the broadest permission levels macOS offers. Granting it to an AI chatbot backed by a company that is currently being sued by Apple for alleged trade secret theft is a decision users should think through carefully.
That lawsuit, filed by Apple in July, accuses OpenAI of hiring Apple employees specifically to extract confidential company information. Against that backdrop, OpenAI shipping a plugin that reads iMessages on Mac feels like a provocation, or at minimum, a very confident move. It is possible Apple has quietly approved the integration. But given their public dispute, it is also possible Apple’s security team is looking at this right now.
For developers and enterprise users evaluating this tool, the functionality is genuinely useful. But the unresolved question of Apple’s position on it should be front of mind before anyone grants an AI full disk access to a work machine.




