ChatGPT macOS Feature Exposes User Data to Infostealers
Key Takeaways OpenAI’s new “Computer History” feature for the ChatGPT macOS app logs user activity in unencrypted, plain-text files. These detailed logs, designed to provide AI...
Key Takeaways
- OpenAI’s new “Computer History” feature for the ChatGPT macOS app logs user activity in unencrypted, plain-text files.
- These detailed logs, designed to provide AI context, are vulnerable to infostealers and other malicious processes on the same macOS user account.
- The feature, released in mid-August 2026, significantly expands the attack surface for the growing number of macOS-targeting infostealers.
- While off by default and requiring explicit user and admin consent, the unencrypted nature of the data poses a substantial risk for data exposure and sophisticated phishing attacks.
- Users handling sensitive information are advised to disable or severely restrict the feature and implement robust macOS security practices.
ChatGPT macOS Feature Exposes User Data to Infostealers
A new capability within the ChatGPT desktop application for macOS, dubbed “Computer History,” creates a comprehensive, unencrypted log of user interactions and activities. This detailed, plain-text record, intended to provide persistent context for the AI assistant, significantly broadens the attack surface for the escalating threat of macOS infostealers, according to security researchers.
Table Of Content
Introduced by OpenAI in mid-August 2026, the Computer History feature is exclusive to the ChatGPT macOS app. Its primary purpose is to enable the AI to understand ongoing work, facilitating responses to generalized requests such as “remind the last person I emailed about the deliveries.” Unlike Microsoft’s controversial Recall feature, which relied heavily on screenshots, OpenAI’s implementation leverages macOS accessibility APIs.
The system meticulously captures a continuous stream of user events, including mouse clicks, typed text, keyboard shortcuts, and application switches. Crucially, it avoids recording screenshots, screen recordings, microphone input, or system audio, differentiating its data collection methodology from other AI memory features.
Deep Dive into Computer History’s Vulnerabilities
Forensic analysis of the Computer History feature revealed an extensive level of data collection. Researchers observed that approximately two hours of typical computer usage generated thousands of logged events, highlighting the granular detail captured by the system.
These raw event files reside temporarily on the user’s machine for up to 48 hours. During this period, ChatGPT initiates hidden background processes that leverage the AI model to condense related events into concise summaries, effectively creating diary-like entries. OpenAI processes these temporary event files on its servers to generate these “memories,” which are then written back to the Mac in plain-text Markdown format. These files are stored within the app’s container at ~/.codex/memories/extensions/skysight/.
Once a summary is generated, the underlying raw activity data is deleted. OpenAI states that it does not retain these background chat sessions or utilize them for model training, except where legally mandated.
The critical vulnerability, acknowledged by OpenAI itself, lies in the fact that these memory files are not encrypted by the Computer History feature. This lack of encryption means that any other program operating under the same macOS user account could potentially read them.
Practically, this implies that highly sensitive information—fragments of emails, chat conversations, and browsing history, already processed and summarized by AI into easily searchable prose—becomes accessible to any process running on the machine, not just the ChatGPT application. This significantly elevates the risk of data compromise.
OpenAI has also issued warnings regarding the feature’s potential to increase the risk of prompt injection attacks. Malicious instructions embedded within a website or application could be captured and integrated into the AI assistant’s context, potentially influencing its subsequent actions.
The Looming Threat: Infostealers and Data Exposure
The timing of this feature’s release coincides with a pronounced surge in macOS-targeting infostealers since 2023, with the underground market for such malware reaching its peak in 2025. Malware families like Atomic macOS Stealer (AMOS), MacSync, and DigitStealer are now routinely observed harvesting sensitive data, including browser credentials, keychain secrets, cryptocurrency wallets, and developer tokens.
Kaspersky researchers documented a sophisticated MacSync variant in September 2026 that combines infostealing capabilities with a backdoor, propagating through trojanized applications disguised as legitimate document-sharing or crypto tools. The rapid evolution of stealer malware, with authors constantly adapting to target new valuable data sources, makes an unencrypted, pre-summarized log of a victim’s daily digital activities an obvious and highly attractive target.
While these memory files do not directly contain passwords or credit card numbers, the rich contextual detail they provide is more than sufficient to craft highly convincing and personalized phishing lures, such as “urgent email from the boss” scenarios.
The exposure extends beyond malware. Any individual with physical access to an unlocked Mac—from a curious colleague to a controlling family member—could quickly access and review a person’s complete work and personal history. Furthermore, individuals with whom the user communicates have not consented to this secondary record; a self-destructing message, for instance, loses its intended privacy if the messaging window itself was not excluded from tracking.
Mitigation and User Controls
OpenAI has implemented several safeguards to limit the feature’s activation and accessibility. Computer History is disabled by default, available exclusively to ChatGPT Pro, Business, and Enterprise subscribers, and requires the “Memories” feature to be active. Enabling it necessitates a deliberate navigation through Settings → Integrations → Computer History, followed by a series of macOS permission prompts; it does not self-activate.
For business accounts, an administrator must grant organization-wide access before individual employees can opt-in. Users retain significant control, including the ability to pause data collection from the menu bar, exclude specific applications and websites, restrict tracking to an allow-list, and delete individual entries or clear data from the last ten minutes, hour, day, or all recorded history.
What You Should Do
- Disable Computer History: For users handling confidential information (e.g., doctors, lawyers, financial professionals), the most prudent course of action is to disable Computer History entirely.
- Configure Exclusions: If the feature is enabled, meticulously add all messaging, financial, and other sensitive applications and websites to the exclusion list. Regularly audit the list of tracked sources.
- Strengthen macOS Security: Implement robust macOS security practices, including locking your Mac when away, disabling auto-login, requiring a password on wake, and enabling FileVault disk encryption.
- Be Vigilant Against Phishing: Understand that even without direct credentials, the contextual information logged by this feature could be used to craft highly convincing phishing attempts. Exercise extreme caution with unsolicited communications.
- Review Privacy Settings: Periodically review all privacy and security settings within the ChatGPT app and your macOS system to ensure they align with your risk tolerance.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.