Apple's New 'Computer History' Feature Addresses Screen Sharing Vulnerability
-
A few weeks back, Apple released several macOS security updates to address a serious vulnerability within its Screen Sharing tool. At the time, the bug hadn't been spotted in the wild. It was more of a "better safe than sorry" type of thing. Now it's actually been found wreaking havoc in the Netherlands, according to a report by Ars Technica.
Compare 1 other version
Ars TechnicaDo you know if your screen sharing is on? The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.
-
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”
Compare 1 other version
EngadgetDutch officials with the Netherlands National Cyber Security Centrum have issued a warning and noted that they received notifications of the vulnerability being used on "multiple systems." In all cases, the attackers received root access and uploaded crypto mining software.
-
ChatGPT’s desktop app on macOS has a new feature called Computer History that turns your actions into training data, learning how you work, suggesting automations, and even picking up tasks you left half done. It uses your activity to build a timeline that ChatGPT and Codex can reference when you make a request.
Compare 1 other version
CNETOpenAI’s ChatGPT chatbot and Codex coding agents have had access to memories, the company’s term for context (background information) derived from previous chat activity, since April 2024. A new Computer History feature builds on that to include (if you opt in) logging your interactions with websites and applications, so it can essentially follow your footsteps to extrapolate where you want to go.
-
ChatGPT’s Computer History tracks your clicks and keystrokes It’s like Windows Recall, but without all the creepy screenshots. (But it’s still kind of creepy.)
Compare 1 other version
CNETIt then periodically synthesizes that activity into a summary of what you’ve done rather than what you saw, heard or said. So, as far as I can tell, it can track and show you where to find files you looked at but not the content of the files. However, if you use that content as part of a future chat, it can link your activity to that content.
-
The feature is opt-in, rather than opt-out, and you can exclude certain apps and websites from Computer History, and you can delete entries if you want finer-grained control. Ari Weinstein, Product and Engineering manager at OpenAI, said on X that Computer History will automatically ignore content in incognito or private browser tabs.
Compare 1 other version
CNETBeyond having the ability to opt in, you can independently select which applications and websites are fair game, as well as pause tracking; you can also view or delete the history at will.
-
The feature is definitely reminiscent of Windows Recall, but where Microsoft’s controversial AI feature relied heavily on screenshots, OpenAI says Computer History doesn’t capture images, videos, or audio, instead relying on “events.”
Compare 1 other version
CNETUnlike Recall and OpenAI’s Chronicle preview, which Computer History replaces, this particular implementation doesn’t capture screens, record voice input or use other similar types of monitoring. Instead, it uses accessibility application programming interface in MacOS to capture everything that API exposes: “clicks, typing, keyboard shortcuts, app switches, and context,” according to the company’s description.
-
These attacks often come in waves. Apple sent out such notifications twice during 2024, warning users about mercenary spyware attacks directed against them. On its notifications page, the company said that it has sent users these warnings multiple times a year and to date has alerted people across more than 150 countries.
Compare 1 other version
CNETApple said in a post this week about the warnings that mercenary spyware attacks are “more sophisticated than regular cybercriminal activity” because attackers target specific people and their devices, making them harder to detect and prevent. Apple did not immediately respond to a request for further comment.
4 details only one outlet reported
Independent claims that didn't surface elsewhere in our corpus. Treat as supplementary — not corroborated across outlets.
-
01 Engadget It lets attackers view your screen, open files and do just about anything else they want.
-
02 ZDNet Google Workspace lets Gemini access your company data by default - how to shut it down
-
03 Wired One of the oddest things about macOS is the installation dance. Dealing with disk images, dragging and dropping—it's the main way of installing software from outside the Mac App Store, and it's annoying.
-
04 CNET The feature launched this week on MacOS for subscribers to its Pro, Business and Enterprise plans (but not yet for users in the European Economic Area, Switzerland or the United Kingdom). According to the documentation, admins for the latter two plans can control whether users have the ability to enable the feature, in addition to individual user opt-in.
Fact Corroboration
Which sources independently confirm the same facts. Hover a claim to see its sources, or a source to see what it corroborates.
Coverage by Perspective
Source Similarity
Connections show how similarly each outlet covered this story. Thicker lines = more similar framing.
Sources (6)
- zdnet
- verge
- wired
- cnet
- engadget
- arstechnica