Technology

OpenAI's ChatGPT Plugin Can Now Read and Send Your Messages on Mac

Martin HollowayPublished 6d ago5 min readBased on 5 sources
Reading level
OpenAI's ChatGPT Plugin Can Now Read and Send Your Messages on Mac
Photo by Arne Müseler / CC BY-SA 3.0 de

OpenAI released a plugin for Apple's Messages app on August 20, 2026, letting ChatGPT on Mac read, search, and respond to iMessage, SMS, and RCS conversations (9to5Mac, MacRumors).

The plugin lets users search their Messages history and draft and send replies through the ChatGPT interface. It handles iMessage, SMS, and RCS conversations on Mac, and is available only on Apple silicon machines (Engadget, OpenAI Help). RCS, or Rich Communication Services, is the modern messaging standard that Android phones use as an upgrade over traditional SMS.

Currently, access is limited to ChatGPT Work and Codex users on Mac (Engadget).

The integration is opt-in. During setup, users must grant ChatGPT access to on-device Messages history, Full Disk Access, contact names, and automation tools (Engadget). That is a broad set of permissions by any standard. Full Disk Access in particular opens the door to far more than Messages data, and the requirement to hand it over to a third-party application is the kind of ask that deserves scrutiny from any security-conscious user or IT department.

Bloomberg reported that the integration could raise privacy and security concerns, per the same Engadget coverage. This is not a hypothetical worry. Apple's Messages ecosystem has been a closely guarded surface, and the company has a track record of aggressive action when third parties attempt to interface with it. In 2024, Apple repeatedly disabled Beeper Mini's access to iMessage until the app's developers gave up trying to re-enable the integration (Engadget). Beeper Mini was an app that let Android users send and receive iMessages, which Apple treated as a security threat.

That Beeper precedent makes the current OpenAI integration all the more striking. Beeper Mini operated without Apple's blessing, reverse-engineering the iMessage protocol to figure out how it worked internally. The ChatGPT plugin, by contrast, uses standard macOS accessibility and automation APIs, requiring explicit per-user permission grants. An API, or application programming interface, is a set of defined channels through which software programs communicate with each other. Apple has not publicly blocked the plugin. Whether that reflects a deliberate policy decision, a different technical approach, or simply a wait-and-see posture is not yet clear from available reporting.

The backdrop is complicated. Apple sued OpenAI in July 2026, accusing the company of trade secret theft, including hiring away Apple employees to obtain confidential company information (Engadget). The lawsuit and the Messages plugin now sit alongside each other as simultaneous threads in the Apple-OpenAI relationship: active litigation on one hand, a new deep integration shipping into Apple's platform on the other. Both companies also participate in Apple's broader ChatGPT integration, which lets users access ChatGPT through Apple's system-level integrations without logging into a ChatGPT account, to ask questions, get help writing messages, or analyze an image (OpenAI Help).

The Messages plugin is distinct from that system-level integration. It operates within the ChatGPT desktop app on Mac, not through Apple's native framework, and requires a ChatGPT Work or Codex subscription rather than functioning without an account. The permission model is also different: the system-level integration leverages Apple's own data-handling pipeline, while the Messages plugin requires direct on-device access granted through macOS privacy controls.

The contrast between how Apple treated Beeper and how it is treating this plugin is worth examining. Beeper Mini gave users iMessage compatibility from non-Apple devices, which Apple framed as a security threat. The ChatGPT plugin gives a third-party AI company the ability to read, search, and send messages through a user's Messages app. The technical mechanisms differ, but the end result in both cases is a third party operating inside Apple's messaging perimeter. That Apple has not intervened here, while actively suing OpenAI on trade secret grounds, suggests the calculus is more nuanced than a simple open-versus-closed platform stance.

Also worth noting: OpenAI retired the Voice experience in the ChatGPT macOS desktop app effective January 15, 2026 (OpenAI Help). The Messages plugin arrives roughly seven months later, which positions the desktop app's feature set as shifting from voice interaction toward deeper system integration.

For enterprise and security teams, the practical question is straightforward. ChatGPT Work users on Mac can now grant a third-party application Full Disk Access and automation permissions, then use it to search and send messages on their behalf. Any organization managing macOS fleets will want to evaluate whether that permission profile fits within its security policies before the feature sees broad adoption. The plugin's restriction to Work and Codex tiers means the surface area is currently bounded to paying users, but permission scopes of this magnitude tend to warrant review regardless of the audience.

The broader context here is what this signals about the Apple-OpenAI relationship. Two companies locked in litigation over trade secrets are simultaneously shipping a deep integration into one of Apple's most sensitive applications. Whether this coexistence holds, or whether the lawsuit eventually forces a retrenchment, will depend on factors well beyond the plugin itself.