Cyber Security News reported on 23 September 2026 that ChatGPT’s Computer History feature, introduced for the Mac app in August, stores an unencrypted record of a user’s activity that other software on the same Mac can read [1]. CyberPress published a similar analysis the same day, citing Kaspersky on the risk this poses to devices already compromised by an information stealer [2]. The feature is opt-in and off by default [3].
Background
OpenAI introduced Computer History for ChatGPT’s Mac app on 13 August 2026, replacing an earlier screenshot-based preview called Chronicle [3]. The feature is off by default; a user enables it in the app’s settings, and Business or Enterprise accounts require administrator approval first [3]. Once enabled, it records interaction events exposed through macOS’s accessibility features — clicks, typed text, keyboard shortcuts, and switching between apps and websites — across the applications a user allows it to observe [3]. It does not capture screenshots, screen recordings, microphone or system audio, or private browsing [3]. Raw events remain on the device for up to 48 hours, after which OpenAI’s servers process them into short written summaries it calls memories; OpenAI states the raw events are not retained afterward or used to train its models [3].
Findings
Cyber Security News reported that the resulting memory files are stored locally as plain-text Markdown, in a folder under the user’s account, and are not encrypted by the feature [1]. CyberPress reported the same file format and location, and stated that in its testing, two hours of ordinary Mac use produced thousands of logged events [2]. Both outlets state that because the files are unencrypted, they can be read by any other process running under the same macOS user account, including established Mac information stealers such as Atomic Stealer, MacSync and one the outlets identify as DigitStealer [1][2].
Citing Kaspersky, CyberPress reported that a harvested memory file could let an attacker impersonate a contact or colleague convincingly, without needing a password, if it reveals “ongoing projects, customer names, email discussions” [2]. Cyber Security News separately noted that the same file is readable by anyone with brief physical access to an unlocked Mac [1].
Implications for Mac users
The risk described applies only to users who have enabled Computer History; the feature ships off, and requires an explicit opt-in [3]. Cyber Security News recommends that users in sensitive professions, including medicine and law, disable the feature outright [1]. Users who have not enabled it are not affected by this specific issue, although the stealers named in the reports already collect other data, such as passwords, browser cookies, cryptocurrency wallets and Keychain contents, independently of this feature [1].
Recommendations
- Check whether Computer History is enabled in ChatGPT’s Settings; it should be off unless it was turned on directly.
- Disable the feature if it is not needed, particularly when handling sensitive client, medical or legal information.
- If it remains enabled, turn on FileVault (System Settings › Privacy & Security › FileVault) so memory files are encrypted at rest, and require a password immediately on sleep.
- Exclude messaging and financial applications from the feature’s tracking, and periodically delete older entries.
- Treat an unlocked, unattended Mac as sufficient exposure on its own, per Cyber Security News’s reporting.
Relevance to FireAI
FireAI does not scan files and does not detect information stealers; it is a network firewall, not antivirus software, and cannot inspect the memory files described in this report. Its function is limited to the point at which data leaves the Mac: it requests approval before an unrecognised application makes its first network connection, shows the destination of a connection on a world map, and in Paranoid mode blocks unsigned applications outright. FireAI’s on-device assistant, Ask FireAI, processes queries locally rather than sending them to a cloud service, unlike the cloud-processing step Computer History uses to generate its summaries. FireAI cannot prevent an already-running process from reading a file under the same user account; it can act only on the network connection that would follow. FireAI is developed by HisnLabs and available to download.
Limitations
Neither report states how Cyber Security News or CyberPress verified that memory files are accessible to other processes, or whether the assessment was tested against a current sample of a named stealer family rather than a general review of file permissions [1][2]. Neither outlet reports a response from OpenAI to the attack-surface claim specifically, and OpenAI’s own description of the feature does not address encryption of the resulting memory files [3]. The number of ChatGPT for Mac users who have enabled Computer History is not reported.