A new feature from OpenAI invites Mac users to let an AI witness their every digital action — every click, every keystroke, every opened window — in exchange for a more contextually aware assistant. The convenience is real, but so is the exposure: the logs it generates sit unencrypted on the user's machine, readable by anything else running under the same account, and the expanded context window opens a door to prompt injection from malicious web content. Security professionals are framing this not as a technical edge case but as a fundamental question about what we are willing to leave lying
OpenAI's Computer History stores unencrypted Mac activity logs, raising security concerns
Leave it off on the work Mac. Use a personal machine with nothing you would have to explain later.
So Computer History is just recording what you do on your Mac and storing it locally. Why is that different from, say, your browser history?
Browser history is just URLs. Computer History is everything—which apps you opened, when you switched between them, what you typed, what you clicked. It's granular. And it's feeding all of that into an AI model that now has context about your entire day.
But OpenAI says the raw files are deleted after 48 hours. Doesn't that limit the damage?
The raw files are, yes. But the summaries—the Markdown files that ChatGPT actually uses—those stay on your machine indefinitely. And they're not encrypted. So the window of vulnerability isn't 48 hours. It's however long you keep those summary files.
Who would actually read those files? You'd need access to your Mac.
Right, but that's the point. Any program running under your user account can read them. Malware, a browser extension, something you installed thinking it was legitimate. You don't need to be a hacker. You just need to be on the same machine.
What about the prompt injection risk? That sounds more abstract.
It's not abstract if you visit a malicious website. The site could embed instructions in its code. ChatGPT reads your Computer History as context, sees those instructions, and executes them. You asked it a question, but it's actually following orders from a webpage you visited.
So the advice is just don't use it?
The advice is: don't use it on a work machine. If you're handling client data, personnel files, financial information, anything you'd have to defend later—leave it off. If you want to try it, use a personal machine with nothing sensitive on it. And don't turn it on just because the feature exists.
That seems like a pretty narrow use case.
It is. Which tells you something about how security experts view the risk-reward calculation here.
Il Polso
- OpenAI's Computer History feature transforms a Mac into a continuous surveillance log of its own user, capturing clicks, keystrokes, and app activity to enrich ChatGPT's memory — a powerful capability that also creates a detailed paper trail.
- The logs are stored as unencrypted plain-text files, meaning any malware or shared-account user can read a full record of someone's work, browsing, and communications without any special access privileges.
- A second, quieter threat lurks in the expanded context: malicious websites can embed hidden instructions that ChatGPT may silently execute when it processes the logged activity, a prompt injection attack the user may never detect.
- OpenAI documents both risks openly, yet ships the feature fully functional for anyone who opts in — leaving the burden of judgment entirely on the user.
- Security experts are unanimous in their guidance: disable it on any work machine, restrict it to personal devices with nothing sensitive, and resist the pull of enabling it simply because it exists.
A new feature from OpenAI invites Mac users to let an AI witness their every digital action — every click, every keystroke, every opened window — in exchange for a more contextually aware assistant. The convenience is real, but so is the exposure: the logs it generates sit unencrypted on the user's machine, readable by anything else running under the same account, and the expanded context window opens a door to prompt injection from malicious web content. Security professionals are framing this not as a technical edge case but as a fundamental question about what we are willing to leave lying around, and for whom.
OpenAI has introduced a feature called Computer History that monitors Mac activity — clicks, keystrokes, app usage — and feeds that behavioral record into ChatGPT's memory, allowing the AI to reference past context in future conversations. The feature is opt-in and off by default, but once enabled, it builds a running timeline of everything a user does on their computer.
The raw interaction data is held temporarily inside the ChatGPT app's own container and deleted after 48 hours. The summaries derived from that data, however, are saved as plain-text Markdown files with no encryption, persisting until the user manually removes them. Because they are unencrypted and stored under the user's account, any other program on the machine — including malware — can read them freely. For anyone handling confidential work, that amounts to leaving a detailed activity log in an unlocked drawer.
A second risk is more insidious. The feature gives ChatGPT a much wider view of what the user has been doing, which means a malicious website could embed hidden instructions in its content. When that browsing session enters the logged context, ChatGPT might act on those injected commands without the user ever noticing. OpenAI acknowledges both vulnerabilities in its documentation.
Security architect Ed Gaile described the feature as the equivalent of a coworker silently transcribing your entire workday and leaving the notes where anyone could find them. His recommendation, shared by other experts, was unambiguous: keep it off on work machines, limit any experimentation to personal devices holding nothing sensitive, and treat availability as a reason for scrutiny rather than adoption.
The feature is currently Mac-only and unavailable in the European Economic Area, Switzerland, and the United Kingdom. Users can restrict which apps and sites contribute to the log, pause collection, or delete history in segments. But the underlying architecture — detailed, unencrypted, broadly accessible — remains unchanged, and for most professionals, the security consensus is simply to leave it disabled.
OpenAI has released a new feature called Computer History that watches what you do on your Mac—every click, every keystroke, every app you open—and feeds that activity into ChatGPT's memory. The feature is off by default and requires you to opt in, but once enabled, it creates a detailed timeline of your computer use, grouping your actions into summaries that the AI can reference in future conversations. Security researchers are now asking whether the convenience is worth the risk.
The feature works by tapping into macOS's accessibility tools to capture interaction events—the raw record of what you're doing. OpenAI says these raw files stay on your machine, isolated inside the ChatGPT app's own data container, and are automatically deleted after 48 hours. But the summaries generated from those events are stored as plain-text Markdown files that remain on your computer until you manually delete them. Those files are not encrypted.
That unencrypted storage is the first problem. Because the files sit in plain text on your Mac, any other program running under your user account can read them. If malware gets onto your machine, or if you share a computer with someone else using the same account, those activity logs become accessible. You're essentially leaving a detailed record of your work, your browsing, your communications—whatever Computer History has captured—sitting in a folder that anything else on your system can open and read.
The second risk is subtler but potentially more dangerous. By feeding ChatGPT a continuous stream of your activity, you're giving the model a much larger context window to work with. That means if you visit a website that contains malicious instructions hidden in its code or content, ChatGPT might follow those instructions. A bad actor could craft a webpage designed to inject commands into your Computer History, and when you ask ChatGPT a question, it might execute those injected instructions without you realizing it. OpenAI acknowledges both risks in its documentation, but the feature ships enabled for anyone who turns it on.
Ed Gaile, a security architect at Appfire, offered a blunt analogy when discussing the feature with Help Net Security: imagine letting a coworker sit next to you all day, writing down every single thing you do, and then leaving those notes in a folder on your desk where anyone could read them. That's Computer History. He was direct in his recommendation: don't turn it on at work. If you want to experiment with the feature, use a personal machine that contains nothing sensitive, nothing you'd have to explain to a client or a manager or a lawyer. And don't enable it just because it's available.
The feature is currently available only on the ChatGPT desktop app for macOS, and it's not available in the European Economic Area, Switzerland, or the United Kingdom—regions with stricter data protection rules. Pro users can turn it on themselves. Business and Enterprise users need administrator approval first. You can choose which apps and websites contribute to your history, pause collection at any time, and delete your history in chunks (the last ten minutes, the last hour, the last day, or everything). But the fundamental architecture remains: detailed activity logs, stored unencrypted, accessible to anything else on your machine. For most people, especially anyone working with confidential information, the security experts are saying the same thing: leave it off.
Citazioni salienti
Would you let a coworker sit next to you all day, write down every click and keystroke, and keep the notes in a folder on your Mac? That is the picture I get when I read about OpenAI's Computer History.— Ed Gaile, Principal Solution Architect at Appfire