There is a (fixed) security issue in Messages for OS X: Recovery of Plaintext iMessage Data Without Breaking Crypto.

Most important takeaway:

While it can be productive for developers to use web technologies … to build desktop applications web application security best practices must still be followed.

This should not be new news for you if you are using this technologies, but obviously it seems to be forgotten easily.

