HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

OpenAI’s ‘Computer History’ Feature Stores Unencrypted macOS Interaction Logs, Raising Infostealer and Prompt‑Injection Risks

OpenAI’s new Computer History add‑on for the macOS ChatGPT app writes raw interaction events to unencrypted local files, exposing them to any program under the same user account. The potential for infostealers to harvest these logs and for prompt‑injection attacks makes the feature a compliance red flag for SOC 2 and privacy regulations.

LiveThreat™ Intelligence · 📅 August 19, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

OpenAI’s “Computer History” Feature Stores Unencrypted macOS Interaction Logs, Raising Infostealer and Prompt‑Injection Risks

What Happened – OpenAI’s new Computer History add‑on for the macOS ChatGPT desktop app records granular interaction events (clicks, keystrokes, app and website usage) and writes them as plain‑text Markdown files inside the app’s container. The raw event files remain on the Mac for 48 hours unencrypted, and the generated memory files persist until the user deletes them.

Why It Matters for Compliance & Audit Readiness

  • Unencrypted local logs constitute a privacy‑by‑design gap that can be flagged during SOC 2 CC 6.2 (confidentiality) assessments and GDPR/CCPA data‑protection reviews.
  • The ability for any program under the same user account to read the logs creates a third‑party data‑exposure vector, requiring documented controls (e.g., file‑system permissions, encryption at rest) and evidence of continuous monitoring.
  • Prompt‑injection risk ties directly to SOC 2 CC 7.1 (risk management) – organizations must demonstrate that AI‑driven tooling does not unintentionally execute malicious instructions.

Who Is Affected – SaaS AI providers, enterprise users of ChatGPT on macOS, and any organization that enables the feature for employees (technology, professional services, finance, etc.).

Recommended Actions

  • Conduct a privacy‑impact assessment (PIA) of the Computer History feature against GDPR/CCPA obligations.
  • Disable the feature or enforce strict file‑system encryption (e.g., FileVault) and limit user‑level access to the ChatGPT container.
  • Update SOC 2 policies to include AI‑assisted tooling controls, and capture evidence of encryption and access‑control settings for audit.

Technical Notes – The feature uses macOS accessibility APIs to capture interaction events; raw JSON event files are stored locally, unencrypted, for 48 hours, while derived Markdown summaries persist until manual deletion. No screenshots or audio are captured, and private‑mode browsing is excluded. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/19/openai-computer-history-privacy-risks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →