---
title: "New ChatGPT Update Brings Apple Messages to Mac"
date: 2026-08-20
author: "Barry Elad"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/08/chatgpt-update-brings-apple-messages-to-mac.jpg"
categories:
  - name: "Artificial Intelligence"
    url: "/artificial-intelligence.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# New ChatGPT Update Brings Apple Messages to Mac

OpenAI added an Apple Messages plugin to the ChatGPT desktop app for macOS in release notes and its own plugin guide flags a known issue with tasks that disable approval prompts. The plugin reads, searches, and sends iMessage, SMS, and RCS chats.

## The Big Picture

- OpenAI’s Apple Messages plugin lets ChatGPT read, search, and send chats in three formats: iMessage, SMS, and RCS.
- OpenAI’s plugin guide names a known issue in which tasks turn off the prompt that asks users to approve sends.
- Apple silicon Macs support the plugin, and Intel Macs cannot run it at all for now.
- ChatGPT Work and Codex can use the plugin, while regular ChatGPT chats cannot reach Messages data.
- Codex thread snapshots redact known secret patterns, though OpenAI warns that sensitive information can still remain.

## OpenAI puts ChatGPT inside Apple Messages

The plugin gives the macOS app direct access to conversations in Apple’s Messages app, where ChatGPT can read, search, and prepare outgoing texts. OpenAI lists it as available on all plans in the ChatGPT desktop app for macOS, with support in both ChatGPT Work and Codex.

OpenAI has drawn two boundaries around it. The plugin does not let anyone drive ChatGPT remotely by texting it, and it does not function in ordinary ChatGPT chats.

Hardware narrows the audience further. [OpenAI’s plugin documentation](https://learn.chatgpt.com/docs/plugins?surface=app#app-use-apple-messages-from-codex) restricts the feature to Apple silicon Macs, which leaves Intel machines out.

> Everyday conversations just got easier with the new Apple Messages plugin.  
>   
> Search messages, catch up on conversations, draft and send replies—all with ChatGPT on your Mac.  
>   
> Now available in ChatGPT Work and Codex on desktop. [pic.twitter.com/nicfZMuxZc](https://t.co/nicfZMuxZc)
> 
> — ChatGPT (@ChatGPT) [August 20, 2026](https://x.com/ChatGPT/status/2090499359641329950?ref_src=twsrc%5Etfw)

 ## The approval gate has a documented gap

OpenAI describes the send step as consent-gated. “**By default, ChatGPT sends messages only after you approve the message and its recipients,**” the company states in the release notes.

That default comes with an exception OpenAI documents itself. The plugin guide covers the risks of granting persistent approval, the steps for revoking access, and a known issue with tasks that disable approval prompts. A task configured that way removes the one control most users assume is always on, a sharper problem than the permission questions raised by [ChatGPT’s advanced security mode](https://sqmagazine.co.uk/openai-chatgpt-advanced-security-mode/).

The documentation confirms the issue and stops there, with no trigger, scope, or fix described. Nothing [OpenAI](https://sqmagazine.co.uk/openai-statistics/) has published says how many users already run tasks configured this way, whether a patch has shipped, or whether a message sent under a suppressed prompt gets flagged afterward.

Four questions sit unanswered in the release notes:

- **Which task configurations disable the approval prompt, and whether that behavior is intended or a defect?**
- **How OpenAI plans to notify users whose existing tasks already skip approval?**
- **Whether the plugin holds on to message content once a session ends?**
- **Whether Intel Mac support is coming at all?**

Anyone who has already granted the plugin persistent approval can revoke it through the steps in OpenAI’s plugin guide, then audit any tasks set up to skip prompts. Reviewing recently sent threads in Messages helps reduce the risk that an outgoing message went unnoticed, though it does not rule that out.

## Codex snapshots and Sites editing round out the release

Codex picked up read-only thread sharing in the same update. A snapshot freezes a local Codex thread at the moment of creation and ignores later changes to the original, and OpenAI redacts known secret patterns before the link goes out. Links from personal accounts open for anyone holding the URL, while workspace links stay inside that workspace.

Redaction has a limit OpenAI states plainly: sensitive information can survive the pass, so snapshots need a read-through before sharing. That caution sits alongside the company’s earlier work on [secret handling in Codex](https://sqmagazine.co.uk/openai-1password-secure-codex/).

Sites gained collaborative editing where owners invite active members of the same workspace. Editors can update content and database data, save versions, and publish changes once the owner completes the first publication, while owners keep control of access, settings, analytics, and version restoration. Some Site owners can also change a **ChatGPT-hosted URL** without redeploying, and the old address redirects to the new one.

## Why It Matters?

Access to a personal message archive changes both what an assistant can do and what it can spill. Reading and searching a **Mac’s iMessage history** makes ChatGPT useful for the retrieval people actually want, such as digging out an address someone texted months ago, and that same reach turns an unapproved send into something far costlier than a bad draft in a chat window. The approval prompt carries the entire safety model here, which is why a documented path to switching it off deserves more attention than any other line in the release notes.

**What happens next** depends on how quickly OpenAI closes the task issue and how loudly it tells affected users. Anyone turning the plugin on now should leave the default approval behavior alone and recheck the plugin’s permissions after setting up any task, because that is the documented route to a send without a prompt. OpenAI named the problem in its own documentation, which sets the bar for how visibly it now has to close it, and its usage numbers put a large audience one toggle away from the answer.