OpenAI's 'Computer History' Feature Raises Privacy Alarms for Mac Users
OpenAI's new 'Computer History' feature for ChatGPT and Codex on macOS creates a timeline of user activity, sparking concerns about potential exposure to information-stealing malware.

OpenAI has introduced a new feature called "Computer History" for its ChatGPT and Codex services, designed to build a timeline of user activity on macOS computers. This feature aims to provide context for the AI by summarizing app usage and website visits, replacing the earlier "Chronicle" research preview with a rebuilt system.
According to OpenAI, Computer History uses interaction events captured through macOS accessibility features to generate these summaries. The company emphasizes that the feature does not include screenshots or record audio, and private web browsing activity is excluded. It is an opt-in feature that requires the separate "Memories" functionality to be enabled and is currently only available through the ChatGPT desktop application on macOS. Users have granular control, able to select which applications and websites contribute to their history and can exclude specific ones. A pause button allows for temporary cessation of data collection without disabling the feature entirely.
Privacy and security experts, however, are voicing significant concerns. Ed Gaile, Principal Solution Architect at Appfire, likened the feature to a coworker meticulously logging every click and keystroke, advising users to avoid enabling it on work computers. He suggests that if the collected data were to be scrutinized in a professional context, it would be highly problematic. Gaile recommends using the feature only on personal machines with non-sensitive data.
Mark Beare, head of Malwarebytes' consumer security unit, echoed these sentiments, warning that the generated memory files could provide information-stealing malware with a detailed map of a user's daily activities. OpenAI itself acknowledges two primary risks: the memory files are not encrypted, potentially allowing other programs on the same user account to access them, and the extensive context provided to the AI increases the risk of prompt injection attacks.
Prompt injection, as described by OpenAI, could lead to ChatGPT or Codex following malicious instructions embedded within a visited website. This means that if a user inadvertently visits a site containing harmful code, the AI might execute it, leading to unintended consequences. The raw interaction-event files are reportedly stored locally on the Mac within the ChatGPT app's data container and are deleted after 48 hours. The generated memory files, which are plain-text Markdown documents, persist until manually deleted by the user.
While OpenAI states that event files are processed on its servers solely for summary generation and are not retained, the local storage of unencrypted data and the potential for prompt injection remain significant security considerations. The feature is also unavailable in the European Economic Area, Switzerland, and the United Kingdom, and requires administrator approval for business and enterprise users before individual opt-in is possible.
The introduction of Computer History highlights a growing tension between AI's utility and user privacy. As AI models become more integrated into daily workflows, the methods used to gather contextual data become increasingly scrutinized. Features that collect detailed user activity, even with opt-in mechanisms and stated privacy safeguards, present new attack vectors for threat actors, particularly information stealers and those employing social engineering tactics through prompt injection.
Users are strongly advised to carefully consider the implications before enabling this feature, especially on devices containing sensitive work-related or personal information. The potential benefits of enhanced AI context must be weighed against the tangible risks of data exposure and exploitation by malicious software.