IT & Adatvédelem
ChatGPT __obi cookie: can it track your browsing?
Cybersecurity analyses suggest ChatGPT places a __obi cookie in the browser that lasts for one year and uses SameSite=None, which could enable tracking across other sites. We summarise what researchers found, what remains uncertain, and how the risk can be reduced.
2026-10-04 · 5 min read
In September 2026, several cybersecurity analyses drew attention to a cookie called __obi, which is placed in users' browsers by the ChatGPT web interface. According to the researchers, this identifier may reach OpenAI even when someone opens a completely different website. We explain what the technical measurements confirmed, where the line lies between proven facts and assumptions, and which simple settings can reduce the chance of tracking.
What is the __obi cookie, and how does OpenAI classify it?
Cookies are small text entries stored in the browser that allow a website to recognise a visitor later. They can include cookies necessary for operation, statistical (analytics) cookies and advertising cookies, and for users this classification usually indicates what they are used for.
According to the OpenAI cookie policy, __obi belongs to the analytics category, operates under the chatgpt.com and openai.com domains, and remains valid for one year. The policy discusses advertising and marketing cookies in a separate group, so based on the company's own description, __obi does not belong to those.
Why does the SameSite=None setting matter?
SameSite is a cookie attribute that determines when the browser may send a cookie. With a stricter setting, the cookie is typically sent only when the user is on the relevant site itself. By contrast, SameSite=None indicates that the cookie may also be attached to requests initiated from other sites, which is one of the technical conditions for cross-site tracking.
According to the analysis by Buchodi's Threat Intel and the Notebookcheck report, __obi is the only OpenAI cookie that has the SameSite=None and Secure attributes. This does not in itself prove misuse, but it explains why researchers noticed it.
How can the identifier reach OpenAI?
According to measurements by Buchodi's Threat Intel, the cookie is set by bzr.openai.com, which the researchers link to OpenAI's advertising collection system called Bazaar. The analysis also states that the identifier is created as a signed token (RS256 JWT) and contains the ChatGPT account identifier. According to the researchers, a stable identifier is also generated when the user is not logged in.
According to the TechWyse report, advertising partner sites use a measurement tool called the OpenAI Measurement Pixel SDK. If the embedded tracking pixel runs on such a site, the browser may also send the __obi cookie to the collection server because of the SameSite=None setting. Based on the NowadAIs analysis, the visited page address, the type of interaction and a timestamp may then be transmitted.
Analytics cookie or advertising tracker?
The core of the debate is the contradiction around its classification. OpenAI's policy describes __obi as an analytics cookie, but according to assessments by Buchodi's Threat Intel and eSecurity Planet, the cookie is tied to advertising infrastructure, so in practice it may serve an advertising measurement and tracking role.
eSecurity Planet also notes that in the case of a chat service, this kind of tracking raises greater privacy concerns than usual. Many users share personal, workplace or health-related questions with ChatGPT, so it is understandable if they react more sensitively to the possibility that the same provider may also receive signals about activity on other sites.
What the measurements do not prove
It is important to distinguish between what researchers can observe from the outside and what happens on the provider's servers. By analysing network traffic, it is possible to verify what information the browser sends and where it goes. What cannot be seen from the outside, however, is whether OpenAI links the incoming information to users' ChatGPT conversations.
The eSecurity Planet analysis also emphasises that the observed traffic does not prove that the company has access to a user's full browsing history. Some analyses go further than this and suggest a direct link between chats and external browsing. At present, however, this is an inference rather than an established fact, so it should be treated with caution.
Safari and iOS: tracking is already limited here
According to eSecurity Planet, built-in protection called Intelligent Tracking Prevention (ITP) blocks these third-party-transmitted cookies in Apple's Safari browser and on iOS devices. Based on the analysis, people who use ChatGPT on these platforms are already much less affected by default.
How can the chance of tracking be reduced?
According to the Notebookcheck report, blocking third-party cookies prevents the __obi identifier from reaching OpenAI from external sites. In most modern browsers, this setting can be found under privacy or cookie-related menu options, although the exact wording may vary by browser and version.
- Block third-party cookies: this appears to be the most effective step, although some embedded functions on certain sites may then work only with limitations.
- Separate browser profile or browser: if someone uses ChatGPT in a separate profile, its cookies are not mixed with those stored during everyday browsing.
- Regularly delete cookies: with an identifier that remains valid for one year, it may be particularly useful to clear stored cookies from time to time.
- Review cookie settings: it is worth checking what consents someone has given on the OpenAI interface and on other sites.
What is worth watching next?
The technical picture described by researchers suggests that, because of its settings, the __obi cookie may be capable of cross-site tracking and is linked to advertising measurement pixels. An open question, however, is whether the company links the collected information to conversations, so it is worth watching whether OpenAI provides a more detailed explanation. Until then, blocking third-party cookies is a simple step that is easy for most users to take. This article is general information and does not constitute legal or privacy advice.
Sources used
- 1.OpenAI Cookie Policyopenai.comverified
- 2.ChatGPT Now Knows What You Do on Other Websites via Ad Collectorbuchodi.comverified
- 3.OpenAI ChatGPT Cookie Cross-Site Tracking Analysisesecurityplanet.comverified
- 4.A ChatGPT __obi cookie-ja követi Önt más weboldalakra isnotebookcheck-hu.comverified
- 5.OpenAI ChatGPT Ad Tracking Cookie __obitechwyse.com
- 6.Inside the __obi cookie: How OpenAI tracks users across sitesnowadais.com
These sources were used during our editorial fact check.