VYPR
researchPublished Sep 23, 2026· 1 source

ChatGPT's 'Computer History' Feature Creates New Attack Surface for macOS Infostealers

OpenAI's new ChatGPT desktop app feature for macOS, 'Computer History,' logs user activity in unencrypted plain text, creating a vulnerability for macOS infostealers.

OpenAI's latest ChatGPT desktop application for macOS introduces a feature named 'Computer History,' which logs user activity in plain text for up to 48 hours. This feature, designed to provide the AI with persistent context for user requests, inadvertently creates a significant new attack surface for the growing number of macOS infostealer malware families.

Security researchers have identified that the 'Computer History' feature, which relies on macOS accessibility APIs to capture interaction events like mouse clicks and typed text, generates detailed logs of user activity. While it avoids screenshots and audio recordings, the sheer volume of logged events can paint a comprehensive picture of a user's digital day. These raw event files are stored unencrypted on the user's machine for up to two days before being processed by OpenAI's servers to generate summaries, which are then saved back to the Mac as plain-text Markdown files.

The critical vulnerability lies in the fact that these memory files are not encrypted. This means any malicious software running with the same user privileges on the macOS system, such as infostealers, can potentially access and exfiltrate this sensitive, pre-summarized data. This data, while not containing direct credentials or financial information, can provide attackers with enough context to craft highly convincing phishing attacks or social engineering schemes.

The timing of this feature's release is particularly concerning given the surge in macOS-targeting infostealers observed since 2023, with families like Atomic macOS Stealer (AMOS), MacSync, and DigitStealer actively harvesting browser credentials, keychain secrets, cryptocurrency wallets, and developer tokens. Threat actors are constantly seeking new, valuable data sources, and an unencrypted, AI-curated log of user activity presents an obvious and lucrative target.

Beyond malware, the feature poses privacy risks for individuals. Anyone with physical access to an unlocked Mac could potentially review a user's recent activities. Furthermore, the feature logs interactions even from applications designed for ephemeral communication, meaning messages that are intended to be self-destructing could still be captured and logged by the 'Computer History' feature.

OpenAI has implemented several safeguards to mitigate risks. The 'Computer History' feature is opt-in, available only to specific subscription tiers (Pro, Business, and Enterprise), and requires explicit user consent through multiple macOS permission prompts. It is not enabled by default and requires users to navigate through settings to activate it. For business plans, administrators must grant organization-wide access before individual users can opt in.

Users who choose to enable the feature have granular control over its operation. They can pause collection, exclude specific applications and websites, restrict tracking to an allow-list, and delete individual entries or clear recent logs. OpenAI states that it does not retain the background chats used for generating memories and does not use them for training purposes, except where legally mandated.

Despite these controls, security experts advise caution, especially for users handling confidential information. For professionals such as doctors, lawyers, or anyone bound by professional secrecy, limiting or disabling 'Computer History' is the most pragmatic recommendation. Those who opt to use it are advised to implement strong Mac login security, enable disk encryption, and regularly audit the list of tracked sources and exclusions.

Synthesized by Vypr AI
ChatGPT's 'Computer History' Feature Creates New Attack Surface for macOS Infostealers · VYPR