OpenAI has begun rolling out Computer History, an opt-in feature for the ChatGPT desktop app on macOS that records user interaction events including clicks, typing, keyboard shortcuts, app switches, and accessibility-exposed context to build a searchable timeline of activity across apps and websites. The capability is available to Pro, Business, and Enterprise users of ChatGPT Work and Codex, and is designed to let ChatGPT answer context-based questions and help locate files, documents, and conversations without relying on continuous screenshots, microphone capture, or system audio.
OpenAI said the feature stores interaction history locally for up to 48 hours and sends event data to its servers to generate memories, while stating that raw event files are not retained after processing unless legally required and are not used for model training. The company also warned that the local history files may contain sensitive information, are not encrypted, and can be accessed by other programs running under the same macOS user account; it further acknowledged increased prompt injection risk from malicious content embedded in websites or apps. Users can exclude apps and sites, pause collection, and delete local data, while Business and Enterprise deployments require admin approval and availability remains delayed or unavailable in the EEA, UK, and Switzerland.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
OpenAI launched an optional, opt-in Computer History feature for the ChatGPT desktop app on macOS for Pro, Business, and Enterprise users. The feature records interaction events such as clicks, typing, shortcuts, and app switches to build a searchable timeline and memory of user activity without continuous screenshots.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.