ChatGPT’s new feature could give infostealers a map of your Mac activity

Help Net Security

Overview

OpenAI's new Computer History feature for ChatGPT and Codex is stirring up concerns regarding user privacy and security. This feature creates a timeline of a user's activities on their Mac, summarizing app usage and website visits. While it aims to enhance user experience by recalling recent activities, it raises alarms that this detailed mapping could be exploited by malicious actors, particularly infostealers. Users could unknowingly expose sensitive information, making them vulnerable to targeted attacks. The implications of this feature stress the need for careful consideration of user data handling and privacy measures.

Key Takeaways

  • Affected Systems: Mac computers using ChatGPT and Codex
  • Action Required: Users should review privacy settings and consider limiting the feature's access to sensitive data.
  • Timeline: Newly disclosed

Original Article Summary

OpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer History does Computer History builds a timeline out of everyday computer use, grouping activity into summaries and noting which apps and websites contributed to each one. “Computer History replaces the earlier Chronicle research preview, but it is a rebuilt system rather … More → The post ChatGPT’s new feature could give infostealers a map of your Mac activity appeared first on Help Net Security.

Impact

Mac computers using ChatGPT and Codex

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Users should review privacy settings and consider limiting the feature's access to sensitive data.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Critical RCE flaw in Windows IKE Extension now actively exploited

BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a serious remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions. This flaw is currently being exploited by attackers, which raises significant concerns for organizations using affected systems. The vulnerability could allow hackers to execute arbitrary code on compromised devices, potentially leading to data breaches or system control. Windows users and administrators are urged to take immediate action to protect their systems. This situation highlights the ongoing risks associated with software vulnerabilities and the importance of timely updates and security measures.

Aug 19, 2026

ICO Urges Police to Improve Data Governance in Facial Recognition Rollouts

Infosecurity Magazine

The UK’s Information Commissioner's Office (ICO) is urging police forces to enhance their data governance practices when implementing facial recognition technology. This recommendation comes amidst concerns about privacy and the potential misuse of data collected through such surveillance systems. The ICO's call emphasizes the importance of adhering to established guidelines to protect individuals' rights and ensure that the technology is used responsibly. As police departments increasingly adopt facial recognition tools, the ICO aims to ensure that these practices are transparent and accountable, addressing public fears over privacy violations. This move is significant as it reflects ongoing debates around surveillance technologies and their implications for civil liberties.

Aug 19, 2026

943 Patches Rolled Out With Oracle’s August 2026 Security Update

SecurityWeek

Oracle has released a significant security update for August 2026, addressing a total of 943 patches that fix over 1,000 vulnerabilities across two dozen of its products. Among these vulnerabilities, more than 460 are considered remotely exploitable, meaning attackers could potentially exploit them from a distance without physical access to the systems. This update is crucial for organizations using Oracle products, as ignoring these vulnerabilities could expose them to significant risks, including data breaches and system compromises. Users are advised to apply these patches promptly to safeguard their systems against potential attacks. The breadth of the vulnerabilities covered in this update highlights the ongoing need for vigilance in software security management.

Aug 19, 2026

Google’s AI security agents found 100+ critical software vulnerabilities in just two days

Help Net Security

Google's Mandiant recently showcased its new AI-driven tool called the Agentic Vulnerability Discovery Harness (AVDH), which successfully identified over 100 severe software vulnerabilities in just two days. This tool was part of a live investigation into compromised corporate repositories and has been operational for ten months. During this period, it has analyzed tens of millions of lines of code. The findings are significant as they indicate that even established software can harbor critical flaws, prompting companies to enhance their security measures. The rapid detection of these vulnerabilities underscores the potential of AI in improving cybersecurity efforts and protecting sensitive data.

Aug 19, 2026

OpenAI puts major frontier AI training run on hold over cyber risks

Help Net Security

OpenAI has decided to pause its major reinforcement learning training run for its latest AI models due to increased cybersecurity concerns. The company is taking this two-week break to strengthen its research environments and improve monitoring practices. This decision comes after a recent incident involving OpenAI and Hugging Face that raised alarms about potential risks. During this pause, OpenAI plans to conduct smaller-scale training and evaluations to better understand the models' behavior and validate existing safeguards. This move is significant as it reflects the company's commitment to ensuring that its AI technologies are safe and aligned with ethical standards before full deployment.

Aug 19, 2026

UK Fraud Cases Hit Record High in 2026

Infosecurity Magazine

Fraud cases in the UK have reached an all-time high, largely driven by incidents of account takeover and identity fraud, according to data from Cifas. The report indicates that these types of fraud are becoming increasingly common, affecting a wide range of individuals and businesses. Account takeover fraud occurs when criminals gain unauthorized access to personal accounts, while identity fraud involves stealing someone's personal information to commit financial crimes. This surge in fraud not only impacts victims financially but also raises concerns regarding the security of personal data and online transactions. As fraudsters become more sophisticated, it emphasizes the need for stronger security measures and awareness among consumers and companies alike.

Aug 19, 2026