Apple Says It Will Tighten macOS Full Disk Access Because AI Agents Raise the Stakes
Apple says macOS will soon require “very explicit user action” before an app gets Full Disk Access, citing AI agents, but it has not said when or how.
Apple said on Friday that it will add new controls around Full Disk Access, the macOS permission that gives an app access to all files on a Mac, citing the growing risks as AI agents become more capable and autonomous. In a short note on its developer news site, Apple wrote that the controls will ensure that users “who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.” The note names no app, no macOS version and no rollout date.
Table Of Content
The timing follows a public dispute over whether Meta’s new Muse agent read a journalist’s private messages, and a run of findings by macOS researcher Patrick Wardle that the desktop apps for AI agents are themselves attractive targets. Apple’s note mentions neither.
What Apple said, and what it left out
The note is two paragraphs. The first describes the trade-off. Apple gives developers “powerful APIs” backed by “a set of controls designed to protect users’ private data,” but “Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac.” Some developers, Apple says, use the permission in ways “that could put users at risk,” exposing “everything on their systems” (files, mail, messages and browsing history) without users’ “full knowledge and understanding.” Then it adds a point that goes beyond the person at the keyboard: “For communication apps, this can also compromise the privacy of the people users are communicating with.”
The second paragraph is about agents: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Apple says it is “committed to ensuring users clearly understand these risks before granting such access.”
Several things are missing:
- When. The Verge reported that Apple does not say when it plans to roll out the update, and Engadget added that the company did not say what exactly would change from the current setup.
- How. The note does not define “very explicit user action.” Apple’s own Privacy & Security guide already describes adding an app to the Full Disk Access list as a manual step: click the add button, select the app in the list, then click Open. Apple has not said what the new requirement adds to that.
- Who. Apple names no developer. Ars Technica noted that Apple did not name Meta, Muse or any other app, and that there are no known reports of other apps abusing the permission to read messages and browsing history.
- Managed Macs. The Privacy Preferences Policy Control payload in Apple’s device management documentation includes a “System Policy All Files” setting, described as access to “data like Mail, Messages, Safari, Home, Time Machine backups, and certain administrative settings for all users of the Mac.” The note does not say whether the new controls will apply to access granted that way.
Apple did not respond to TechCrunch’s inquiry about the change, and The Verge reported that Apple had not immediately responded to its request for comment.
What Full Disk Access gives an app
Apple’s guide describes the permission as one that lets apps “access all files on your computer, including data from other apps (for example, Mail, Messages, Safari, and Home), data from Time Machine backups, and certain administrative settings for all users on this Mac.” Wardle, a longtime macOS researcher at the Objective-See Foundation, put it more bluntly to Ars Technica: with Full Disk Access, “any (non-root file), is readable.”
That breadth is why agent developers ask for it. Engadget reported that desktop clients for AI agents such as OpenClaw, Dots and Muse often encourage users to grant the permission so the agents can reach their files, messages and other data. Apple’s remark about communication apps points at the other side of that bargain: the people in a user’s message threads never made any choice about Full Disk Access.
The Muse dispute behind the timing
Apple did not name Meta or Muse. Ars Technica’s Dan Goodin wrote that the statement may not refer to Muse at all, but that the timing, “on the heels of a major social media uproar,” makes that connection likely.
The incident comes from an Inc. column by Jason Aten, which was not retrievable for this report, so the account below relies on summaries from Decrypt and The Next Web. Aten installed Muse on an iPhone and a Mac mini. He says he declined to give it access to his messages during setup and checked afterward that Full Disk Access was off. Muse then pitched him a column idea based on a private text exchange with his podcast co-host and flagged a message from his editor. When he asked how it knew, Muse said it had only seen notification banners. Aten says he then found that Muse had synced his Messages database up to row 187,462.
Meta disputes the account. Communications chief Andy Stone wrote on X on Wednesday that the Messages integration in the Mac app is “entirely opt-in” and that a user has to “enable both Full Disk Access and the Messages connector.” Meta executive David Singleton made the same point, saying, as quoted by Ars Technica, that “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.” The Next Web adds that Singleton said macOS protections cannot be bypassed even if the Muse app had a bug, and Decrypt reports that he called the notification explanation Muse gave Aten wrong.
The two accounts conflict on a factual point. Aten says the permission was off and the data synced anyway; Meta’s position is that Muse cannot read Messages without it. The reports reviewed here describe no independent reproduction either way, and Apple’s note does not settle it.
Our reading (analysis, not a claim by Apple or Meta): Decrypt describes the Messages connector as “Muse’s own on/off switch for that app.” That makes it a setting inside Muse, which macOS does not manage. Of the two switches Stone describes, only Full Disk Access is one that macOS itself enforces, and by Apple’s own description it “largely sidesteps” the controls that otherwise protect private data. That is the switch Apple now says it will put extra controls around.
Wardle’s findings: the agent app is the target
Wardle has been documenting a second risk, that an agent app’s own access can be turned against its owner. The Hacker News reported on Sept. 22 that his proof of concept, released Sept. 21, lets malware already running on a Mac take over Muse and use the access its owner granted the app. The trick is an undocumented setting, endo_voyager_dictation_endpoint, that decides where Muse sends dictation; any program running as the logged-in user can point it at an address the attacker controls “without needing extra permissions.” Wardle said he did not report the flaw to Meta before going public, and WIRED says it has since been patched. As of The Hacker News’s report, Meta had not published a security advisory.
WIRED reported on Friday that researchers at the Objective-See Foundation, where Wardle works, found a different flaw with the same precondition, malware already on the Mac, in OpenAI’s ChatGPT app for macOS. The app’s components verify each other’s digital signatures, including those of a process’s parent and grandparent, and Wardle said a malicious script could satisfy the checks by spawning a trusted script interpreter three times. He called the bug “insanely trivial” to exploit, with a proof of concept of about a dozen lines of code. WIRED says OpenAI acknowledged the fix in its system change log on Sept. 25.
“Agents need a lot of access to do their job,” Wardle told WIRED. “They are like the building manager who has access to the keys to all the rooms.” He said he has submitted a new finding to OpenAI about the integration between ChatGPT and its always-on Dots assistant, and that he plans to present more macOS AI-app bugs at the Objective by the Sea conference in November.
What Mac users and admins can do now
- Open System Settings, then Privacy & Security, then Full Disk Access, and review which apps hold it. Switch it off for any agent or assistant that does not need it; Meta’s Stone said users can switch Muse’s access off at any time.
- Treat Terminal commands from websites, chats or messages as hostile. Wardle told The Hacker News that a remote attacker could hijack Muse through a ClickFix trick, which fools the user into running a single command.
- On managed Macs, list the configuration profiles that allow “System Policy All Files” for agent apps, and plan to re-test them once Apple ships the change, since the note does not say how managed grants will be treated.
- Watch Apple’s macOS release notes. The note gives no schedule.
Related coverage on sxz.io: Amazon blocks Meta’s Muse agent from shopping, OpenAI launches Dots and says it is still fixing known vulnerabilities, and NVIDIA’s open agent safety platform, which puts security outside the agent’s reach.








No Comment! Be the first one.