OpenAI's new ChatGPT Computer History feature for macOS aims to enhance AI assistance with context-aware capabilities, but it could also attract macOS infostealers. The feature, enabled by default for ChatGPT Pro, Business, and Enterprise users, records user activity locally, potentially creating a valuable target for attackers. The feature collects typed text, clicks, keyboard shortcuts, app switches, window titles, and other interface activities from selected apps and sites.
This architecture serves as an attractive entry point for macOS infostealers. Malware operators typically target browser credentials, cryptocurrency wallets, keychain data, session cookies, API tokens, and saved passwords.
Kaspersky noted that an attacker might not need a password if a harvested memory file reveals ongoing projects, customer names, email discussions, internal tools, financial platforms, delivery disputes, or a manager's writing style. However, organizations dealing with sensitive client, legal, healthcare, financial, or security information should consider Computer History as a data governance decision, not a simple productivity feature. For security teams, the feature introduces a new detection priority: macOS infostealers should look for suspicious access to ChatGPT and Codex memory directories, particularly processes reading or exfiltrating files from .codex/memories.
Restricting Computer History to a narrowly defined allow-list, enabling FileVault, enforcing rapid screen locking, and maintaining endpoint protection can reduce exposure, but for high-risk users, disabling the feature entirely remains the safest option.




![Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Decentralized-Identity-Solutions-1.webp)







