The Information Machine
Concluded·following since 13 Aug 2026·Day 2·10 sources·updated 18 Aug 2026

ChatGPT Mac's Computer History feature

The gist

OpenAI launched Computer History for ChatGPT's Mac app, tracking desktop activity; memory files stored unencrypted locally

The feature gives ChatGPT persistent awareness of desktop activity across sessions, but OpenAI's own documentation confirms the generated memory files are unencrypted and accessible to any process running under the same macOS user account. The feature also expands ChatGPT's prompt-injection attack surface by feeding content from every allowed app and website directly into the model's context.

The full picture

Computer History is an opt-in feature in ChatGPT's Mac desktop app that records user activity across permitted apps and websites using macOS accessibility APIs, capturing clicks, typing, keyboard shortcuts, and app switches rather than screenshots or audio. Temporary event files are stored locally for up to 48 hours, after which OpenAI processes them server-side to generate memories written back to the Mac as plain-text Markdown files. OpenAI's own documentation states those memory files are not encrypted and that other programs running as the same macOS user can potentially read them. The feature replaces the earlier Chronicle research preview, which relied on screenshots; Computer History does not capture screen images, microphone input, or system audio, and OpenAI says it uses fewer tokens and offers more privacy controls than Chronicle. It also extends context to Codex. Users can query their recorded activity with natural language prompts, such as requesting a task status list or locating a document worked on the previous day. Controls allow excluding specific apps and websites and deleting entries, and the Memories option must be enabled for activity to persist across sessions. OpenAI has acknowledged that malicious instructions embedded in apps or websites could be captured into the activity context, constituting a prompt-injection risk. Security researchers have previously demonstrated that ChatGPT's memory system can be exploited via prompt injection to exfiltrate chat history and stored memories to an attacker-controlled server; OpenAI fixed that specific vulnerability.

How it developed
18 August 2026

Coverage arriving August 18 added details to OpenAI's August 13 launch of Computer History, an opt-in Mac feature that records clicks, typing, and app switches and writes plain-text memory files after server-side processing.

Digital Trends cited OpenAI's own documentation warning that other programs running under the same macOS user can read those unencrypted files. Security researchers documented a prior prompt injection attack that exfiltrated ChatGPT chat history to an attacker-controlled server, which OpenAI fixed, though Computer History's feed from every permitted app keeps the injection surface broader.

13 August 2026

OpenAI announces and launches Computer History as opt-in feature in ChatGPT Mac desktop app

Sources
5 more sources
The daily email

Want this in your inbox?

I send a short email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free