A new AI assistant feature on the Mac records everyday clicks and typed text into memory files stored in plain text, where security researchers say any other program running under the same user account can quietly read them.
The tool, called Computer History, ships inside the ChatGPT desktop app for macOS and compiles a diary of app and website use that the assistant and its coding companion Codex can consult. OpenAI positions it as a ground-up rebuild of an earlier experiment named Chronicle. Data collection leans on macOS accessibility hooks to pull in interaction events, text, and context. Screenshots, audio, and private-mode browsing stay out of the record.
The feature defaults to off and needs the separate Memories capability switched on first. Pro subscribers can enable it directly, while Business and Enterprise accounts require administrator sign-off. It does not operate in the European Economic Area, Switzerland, or the United Kingdom, and it runs only in the macOS desktop app. Users can pause recording, blacklist apps and sites, and erase the last ten minutes, hour, day, or all of it. Raw activity files expire from the app’s sandboxed storage after 48 hours.
OpenAI admits two weaknesses itself. The persistent memory files are not encrypted, so other software running as the same macOS user may be able to open them, and constant activity context raises the odds of instruction-hijacking attacks in which a hostile webpage could make ChatGPT or Codex follow its orders. Those notes, written as readable Markdown, stay behind until someone deletes them, while the server-side copies used to assemble summaries are discarded. Malwarebytes consumer chief Mark Beare said the files hand infostealers a ready-made map of a person’s workday, and Appfire architect Ed Gaile urged keeping the feature off on work machines.