ChatGPT Computer History Feature Creates New Attack Surface for macOS Infostealers
OpenAI's new ChatGPT 'Computer History' feature for macOS logs user actions in unencrypted text, creating a high-value target for infostealers.
OpenAI's new 'Computer History' feature for the ChatGPT macOS desktop app, which logs user actions to provide persistent context, creates a new attack surface. The feature saves AI-summarized user activity as unencrypted plain-text Markdown files, which are accessible to other processes on the same Mac. Security researchers warn this makes the files a prime target for a surge in macOS infostealers like AMOS and MacSync, which can now harvest pre-summarized data of a victim's digital activity. OpenAI has acknowledged the risk and states the feature is off by default.
- OpenAI's new 'Computer History' feature in ChatGPT for macOS logs user actions in plain text.
- The unencrypted memory files are accessible to other processes on the same user account.
- This creates a high-value target for macOS infostealers like AMOS and MacSync.
- The feature also increases the risk of prompt injection attacks.
Full article818 words · extracted from cybersecuritynews.com · click to collapse
A new feature in ChatGPT now records your actions on your Mac, creating a detailed, plain-text diary of your work. This unencrypted log is vulnerable to cybercriminals, offering them an easy target.
Released by OpenAI in mid-August 2026 and available only in the ChatGPT desktop app for macOS, the feature is called Computer History, and security researchers warn that it materially widens the attack surface for the wave of macOS infostealers currently flooding the threat landscape.
Computer History is designed to give the AI assistant persistent context about your work, so it can handle vague requests such as “remind whoever I emailed last week about the deliveries.” Rather than following the screenshot-heavy approach that made Microsoft’s Recall a public-relations liability, OpenAI built the feature on top of macOS accessibility APIs.
It captures a stream of interaction events mouse clicks, typed text, keyboard shortcuts, and app switching and explicitly avoids screenshots, screen recordings, microphone input, and system audio.
ChatGPT Computer History Feature
Forensics researchers testing the feature reported that roughly two hours of ordinary computer use generated thousands of logged events, illustrating just how granular the collection is.
Those raw event files linger on the machine for up to 48 hours. During that window, ChatGPT periodically runs hidden background sessions that ask the model to condense related events into short recaps, essentially diary entries.
OpenAI processes the temporary event files on its own servers to generate these memories, then writes the finished summaries back to the Mac as plain-text Markdown inside the app’s container at ~/.codex/memories/extensions/skysight/.
Once a summary is produced, the underlying raw activity is deleted, and OpenAI says it does not retain the background chats or use them for training except where legally required.
The critical weakness is disclosed by OpenAI itself: the memory files are not encrypted by Computer History, and other programs running under the same macOS user account may be able to read them.
In practical terms, that means a copy of the most sensitive parts of your emails, chats, and browsing already distilled by AI into clean, searchable prose is available to any process on your machine, not just the ChatGPT app.
OpenAI has also warned that the feature raises the risk of prompt injection, because malicious instructions embedded in a website or application could enter the context the assistant later acts on.
This is where the timing becomes dangerous. macOS-targeting infostealers have surged since 2023, with underground demand and supply peaking in 2025, and families such as Atomic macOS Stealer (AMOS), MacSync, and DigitStealer now routinely harvest browser credentials, keychain secrets, cryptocurrency wallets, and developer tokens.
Kaspersky researchers documented a reworked MacSync variant in September 2026 that pairs an infostealer with a backdoor and spreads through trojanized apps disguised as document-sharing or crypto tools. Stealer authors iterate fast and constantly retarget whatever data looks valuable, so an unencrypted, pre-summarized log of a victim’s entire digital day is an obvious next target.
While no passwords or card numbers live in these files, the contextual detail is more than enough to craft a convincing “urgent email from the boss” style phishing lure.
The exposure is not limited to malware. Anyone with physical access to an unlocked Mac a nosy coworker or a controlling family member — could read a person’s work and personal history in minutes. Worse, the people you communicate with never consented to this second copy; a self-destructing message means nothing if the messaging window itself was not excluded from tracking.
OpenAI has, to its credit, built more friction than Recall ever had. Computer History is off by default, available only to Pro, Business, and Enterprise tiers, and requires Memories to be enabled. Turning it on demands a deliberate journey through Settings → Integrations → Computer History, plus a series of macOS permission prompts, and it never activates itself.
On business plans, an administrator must grant organization-wide access before each employee opts in separately. Users can pause collection from the menu bar, exclude specific apps and sites, restrict tracking to an allow-list, and delete individual entries or clear the last ten minutes, hour, day, or everything.
For anyone handling confidential material doctors, lawyers, and others bound by professional secrecy the pragmatic recommendation is to limit or disable Computer History outright.
Those who still want to test it should lock down Mac login, disable auto-login, require a password on wake, enable FileVault disk encryption, add every messaging, finance, and sensitive app to the exclusion list, and audit the tracked-sources list at least twice a week.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.