ChatGPT Computer History Feature Creates New Data Theft Risk for macOS Infostealers
OpenAI's ChatGPT Computer History feature creates a new data theft risk by storing user activity in readable Markdown files accessible to malware.
OpenAI's new ChatGPT Computer History feature for macOS, which converts user activity into readable Markdown files, creates a new data theft risk for macOS-based infostealers. The feature tracks interactions and summarizes them into local memory files, which malware could access to gather a concise overview of a user's activities. This could enable more effective social engineering and extortion attacks.
- OpenAI's ChatGPT Computer History feature creates a new data theft risk for macOS infostealers.
- The feature converts user activity into readable Markdown files, providing a concise overview of workflow.
- Infostealers could exploit these files to gather sensitive information for social engineering or extortion.
Full article733 words · extracted from gbhackers.com · click to collapse
OpenAI’s new ChatGPT Computer History feature for macOS aims to enhance AI assistance by making it more context-aware. However, it also creates a potential risk of local data leaks that macOS-based infostealers could exploit.
This feature converts user activity into readable, diary-like memory files that may expose sensitive work-related information to malware running under the same user account.
ChatGPT History Feature New Data Theft
Launched in mid-August 2026, Computer History is an opt-in feature available in the ChatGPT desktop app for macOS.
It is accessible to ChatGPT Pro, Business, and Enterprise users, requires the activation of ChatGPT Memories, and is disabled by default. Users in Business and Enterprise plans must obtain administrator approval before activating it.
Instead of taking continuous screenshots, like Microsoft Recall, this feature utilizes macOS Accessibility APIs to create a stream of interaction events from authorized applications and websites. The features it tracks include:
- Mouse clicks and interface interactions
- Text input in fields
- Keyboard shortcuts
- App switching
- Window titles and user interface text visible through macOS
- Browser page context, such as site names and readable text
OpenAI clarifies that Computer History does not capture screenshots, screen recordings, microphone audio, or system audio. Private browsing windows are excluded, and masked password fields are not accessed.
Raw event data can remain accessible locally for up to 48 hours. ChatGPT periodically summarizes this activity into “memories,” which can later be searched during ChatGPT or Codex sessions. These local memory files are stored at the following path:
~/.codex/memories/extensions/skysight/
According to kaspersky, the summaries may contain a condensed record of emails read, websites visited, documents accessed, tasks performed, individuals contacted, and overall workflow activity.
The primary security concern is not that Computer History directly records passwords or financial information.
Instead, the risk lies in its ability to convert sensitive activities into structured plain-text Markdown files that other programs operating under the same macOS user account may access. OpenAI’s documentation reportedly acknowledges that other applications on the device may be able to access these local files.
This creates an attractive target for information-stealing malware. Previously, infostealers would need to gather browser history, cookies, files, wallet extensions, and credentials from various locations. Now, they could obtain AI-generated summaries that provide a concise, human-readable overview of a user’s activities.
For instance, a memory file might show that a finance employee reviewed a supplier invoice, communicated with a specific executive, and prepared a spreadsheet related to payments.
This context could enable an attacker to launch a convincing business email compromise without requiring password information.
The timing of this feature is significant, as macOS-targeted infostealers continue to evolve. Kaspersky has recently reported an updated MacSync campaign that combines infostealing capabilities with a backdoor, targeting browser data, credentials, cryptocurrency information, and wallet-related data.
Computer History adds another layer of data collection: workflow intelligence. Cybercriminals could leverage stolen histories to identify internal projects, trusted contacts, financial transactions, confidential client matters, and high-value social-engineering targets.
Additionally, the feature may increase exposure for users of disappearing messaging services. Even if a messaging platform removes a message from its interface, a Computer History summary could retain contextual details about that conversation if the app or website was included in the tracking.
Organizations should treat Computer History as a critical data governance and endpoint security issue, not merely a productivity feature.
- Keep the feature disabled on Macs used for sensitive tasks such as privileged administration, finance, healthcare, legal work, incident response, source communications, or confidential research.
- If the feature is enabled, use the “Include only these apps” and “Include only these websites” settings instead of broad monitoring.
- Explicitly exclude messaging, email, finance, HR, password management, customer data, and internal administration applications.
- Regularly review Computer History entries and delete summaries containing sensitive material.
- Enforce FileVault, immediate screen locking, strong authentication, and modern endpoint protection that can detect macOS infostealers.
- Monitor the `~/.codex/memories/extensions/skysight/` directory as a potentially sensitive local data store.
Computer History improves context retention but also creates new data-theft opportunities. An attacker who compromises a Mac may gain access not only to credentials and browser artifacts but also to an AI-curated narrative of the victim’s professional and personal activities.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.