$ techbeacon▋
CVE & Exploits

OpenAI’s macOS ‘Computer History’ Feature Raises Concerns Over New Infostealer Threats

OpenAI’s macOS ‘Computer History’ Feature Raises Concerns Over New Infostealer Threats

OpenAI has rolled out a new "Computer History" capability for its ChatGPT app on macOS, a tool designed to let the AI reference a user’s recent on‑device activity in order to provide more context‑aware assistance. While the feature promises smoother workflows, security researchers warn that it also opens a fresh avenue for malware that harvests locally stored data.

The functionality works by continuously logging application usage, window titles, and file interactions, then feeding that information to the language model when a user asks for help. In theory, the AI can suggest relevant shortcuts, retrieve recent documents, or troubleshoot issues based on what the user has been doing moments before. OpenAI describes the approach as a privacy‑first design, keeping the data on the device and only transmitting it to the model after local encryption.

However, the same local cache that enables the feature can be accessed by any program with sufficient privileges. Security analysts note that macOS‑based infostealers—malware that silently gathers personal information—could be modified to read the Computer History logs and exfiltrate them. Because the logs may contain file names, URLs, and even snippets of text from opened documents, the breach could expose sensitive corporate or personal data without the user’s knowledge.

Researchers at GBHackers, who first highlighted the issue, point out that the risk is not limited to newly written malware. Existing trojans that already target macOS keychains or clipboard data could be updated to include the new log files in their payloads, amplifying their impact. The problem is compounded by the fact that macOS permissions for accessing certain system directories are often granted during initial app installation, and users may not be prompted again when the logs are read.

OpenAI has responded that the logs are stored in a sandboxed location and encrypted with a key derived from the user’s device credentials. The company also says that the feature can be disabled in the app’s settings, and that future updates will add additional safeguards such as stricter access controls and optional user consent dialogs before any data leaves the machine.

Industry observers suggest that the episode underscores the tension between AI convenience and security on personal computers. As AI assistants become more tightly integrated with operating systems, developers will need to balance seamless functionality with robust threat modeling. For now, experts recommend that macOS users who are concerned about data leakage either turn off the Computer History feature or monitor the permissions granted to third‑party applications, especially those that request broad file system access.

Source: GBHackers
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related