TRENDING
Close-up of the Rosetta Stone showing the Demotic script above and the Greek script below, the same text written in two different scripts
October 6, 2026
How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs
A row of green and grey fibre broadband street cabinets on a pavement beside a fence in Iver, England
October 6, 2026
BT’s TalkTalk Rescue Turns Telecom Continuity Into a New Merger-Control Ground
An ornate cast-iron wall mailbox with its door hanging open, stuffed with colorful flyers and a yellow flyer bulging out of the top slot
October 6, 2026
Google Stops Accepting Product Bug Reports for Its Open-Source Bounty, Citing Automated Submissions
Chronophotograph by Étienne-Jules Marey of a man riding a bicycle, showing five snapshots of the same ride taken at regular intervals
October 6, 2026
How to Find Slow Python Code With the Python 3.15 Tachyon Sampling Profiler
Close-up of an airport baggage tag reading Stockholm Arlanda and ARN
October 6, 2026
Cloudflare Traces Turns Distributed Tracing Into a Trust Decision at the Edge
06 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Shelves of old books fastened by iron chains in the Francis Trigge Chained Library in Grantham, England, a picture of data that can be read but not changed
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
October 5, 2026
Row of capsule hotel pods with white pillows and folded blankets, each capsule an idle sleeper packed into a shared rack
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
October 5, 2026
Denmark’s oldest church book, from Holmens parish, open on a stack of books; its handwritten pages record births between 1617 and 1639
Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
October 5, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 226 Posts
News 228 Posts
Learning Hub 198 Posts
Home/News/Apple Says It Will Tighten macOS Full Disk Access Because AI Agents Raise the Stakes
News

Apple Says It Will Tighten macOS Full Disk Access Because AI Agents Raise the Stakes

Apple says macOS will soon require “very explicit user action” before an app gets Full Disk Access, citing AI agents, but it has not said when or how.

October 3, 2026 6 Min Read
20

Apple said on Friday that it will add new controls around Full Disk Access, the macOS permission that gives an app access to all files on a Mac, citing the growing risks as AI agents become more capable and autonomous. In a short note on its developer news site, Apple wrote that the controls will ensure that users “who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.” The note names no app, no macOS version and no rollout date.

Table Of Content

  • What Apple said, and what it left out
  • What Full Disk Access gives an app
  • The Muse dispute behind the timing
  • Wardle’s findings: the agent app is the target
  • What Mac users and admins can do now

The timing follows a public dispute over whether Meta’s new Muse agent read a journalist’s private messages, and a run of findings by macOS researcher Patrick Wardle that the desktop apps for AI agents are themselves attractive targets. Apple’s note mentions neither.

What Apple said, and what it left out

The note is two paragraphs. The first describes the trade-off. Apple gives developers “powerful APIs” backed by “a set of controls designed to protect users’ private data,” but “Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac.” Some developers, Apple says, use the permission in ways “that could put users at risk,” exposing “everything on their systems” (files, mail, messages and browsing history) without users’ “full knowledge and understanding.” Then it adds a point that goes beyond the person at the keyboard: “For communication apps, this can also compromise the privacy of the people users are communicating with.”

The second paragraph is about agents: “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.” Apple says it is “committed to ensuring users clearly understand these risks before granting such access.”

Several things are missing:

  • When. The Verge reported that Apple does not say when it plans to roll out the update, and Engadget added that the company did not say what exactly would change from the current setup.
  • How. The note does not define “very explicit user action.” Apple’s own Privacy & Security guide already describes adding an app to the Full Disk Access list as a manual step: click the add button, select the app in the list, then click Open. Apple has not said what the new requirement adds to that.
  • Who. Apple names no developer. Ars Technica noted that Apple did not name Meta, Muse or any other app, and that there are no known reports of other apps abusing the permission to read messages and browsing history.
  • Managed Macs. The Privacy Preferences Policy Control payload in Apple’s device management documentation includes a “System Policy All Files” setting, described as access to “data like Mail, Messages, Safari, Home, Time Machine backups, and certain administrative settings for all users of the Mac.” The note does not say whether the new controls will apply to access granted that way.

Apple did not respond to TechCrunch’s inquiry about the change, and The Verge reported that Apple had not immediately responded to its request for comment.

What Full Disk Access gives an app

Apple’s guide describes the permission as one that lets apps “access all files on your computer, including data from other apps (for example, Mail, Messages, Safari, and Home), data from Time Machine backups, and certain administrative settings for all users on this Mac.” Wardle, a longtime macOS researcher at the Objective-See Foundation, put it more bluntly to Ars Technica: with Full Disk Access, “any (non-root file), is readable.”

That breadth is why agent developers ask for it. Engadget reported that desktop clients for AI agents such as OpenClaw, Dots and Muse often encourage users to grant the permission so the agents can reach their files, messages and other data. Apple’s remark about communication apps points at the other side of that bargain: the people in a user’s message threads never made any choice about Full Disk Access.

The Muse dispute behind the timing

Apple did not name Meta or Muse. Ars Technica’s Dan Goodin wrote that the statement may not refer to Muse at all, but that the timing, “on the heels of a major social media uproar,” makes that connection likely.

The incident comes from an Inc. column by Jason Aten, which was not retrievable for this report, so the account below relies on summaries from Decrypt and The Next Web. Aten installed Muse on an iPhone and a Mac mini. He says he declined to give it access to his messages during setup and checked afterward that Full Disk Access was off. Muse then pitched him a column idea based on a private text exchange with his podcast co-host and flagged a message from his editor. When he asked how it knew, Muse said it had only seen notification banners. Aten says he then found that Muse had synced his Messages database up to row 187,462.

Meta disputes the account. Communications chief Andy Stone wrote on X on Wednesday that the Messages integration in the Mac app is “entirely opt-in” and that a user has to “enable both Full Disk Access and the Messages connector.” Meta executive David Singleton made the same point, saying, as quoted by Ars Technica, that “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.” The Next Web adds that Singleton said macOS protections cannot be bypassed even if the Muse app had a bug, and Decrypt reports that he called the notification explanation Muse gave Aten wrong.

The two accounts conflict on a factual point. Aten says the permission was off and the data synced anyway; Meta’s position is that Muse cannot read Messages without it. The reports reviewed here describe no independent reproduction either way, and Apple’s note does not settle it.

Our reading (analysis, not a claim by Apple or Meta): Decrypt describes the Messages connector as “Muse’s own on/off switch for that app.” That makes it a setting inside Muse, which macOS does not manage. Of the two switches Stone describes, only Full Disk Access is one that macOS itself enforces, and by Apple’s own description it “largely sidesteps” the controls that otherwise protect private data. That is the switch Apple now says it will put extra controls around.

Wardle’s findings: the agent app is the target

Wardle has been documenting a second risk, that an agent app’s own access can be turned against its owner. The Hacker News reported on Sept. 22 that his proof of concept, released Sept. 21, lets malware already running on a Mac take over Muse and use the access its owner granted the app. The trick is an undocumented setting, endo_voyager_dictation_endpoint, that decides where Muse sends dictation; any program running as the logged-in user can point it at an address the attacker controls “without needing extra permissions.” Wardle said he did not report the flaw to Meta before going public, and WIRED says it has since been patched. As of The Hacker News’s report, Meta had not published a security advisory.

WIRED reported on Friday that researchers at the Objective-See Foundation, where Wardle works, found a different flaw with the same precondition, malware already on the Mac, in OpenAI’s ChatGPT app for macOS. The app’s components verify each other’s digital signatures, including those of a process’s parent and grandparent, and Wardle said a malicious script could satisfy the checks by spawning a trusted script interpreter three times. He called the bug “insanely trivial” to exploit, with a proof of concept of about a dozen lines of code. WIRED says OpenAI acknowledged the fix in its system change log on Sept. 25.

“Agents need a lot of access to do their job,” Wardle told WIRED. “They are like the building manager who has access to the keys to all the rooms.” He said he has submitted a new finding to OpenAI about the integration between ChatGPT and its always-on Dots assistant, and that he plans to present more macOS AI-app bugs at the Objective by the Sea conference in November.

What Mac users and admins can do now

  • Open System Settings, then Privacy & Security, then Full Disk Access, and review which apps hold it. Switch it off for any agent or assistant that does not need it; Meta’s Stone said users can switch Muse’s access off at any time.
  • Treat Terminal commands from websites, chats or messages as hostile. Wardle told The Hacker News that a remote attacker could hijack Muse through a ClickFix trick, which fools the user into running a single command.
  • On managed Macs, list the configuration profiles that allow “System Policy All Files” for agent apps, and plan to re-test them once Apple ships the change, since the note does not say how managed grants will be treated.
  • Watch Apple’s macOS release notes. The note gives no schedule.

Related coverage on sxz.io: Amazon blocks Meta’s Muse agent from shopping, OpenAI launches Dots and says it is still fixing known vulnerabilities, and NVIDIA’s open agent safety platform, which puts security outside the agent’s reach.

Tags:

AI AgentsAI SecurityAppleData PrivacymacOSMeta

Share

An open smoke sensor showing its green circuit board, black optical detection chamber and battery clip
Previous Post

How to Catch a Malicious Python Package at Import Time With Audit Hooks

Seven lines of Latin verse in capital letters with no spaces between the words, from a late antique manuscript of Virgil
Next Post

Trail of Bits’ SequenceHash Turns Hash-Concatenation Bugs Into a Specification Problem

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
05 Oct
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
05 Oct
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
Trending
October 5, 2026
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
October 5, 2026
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
October 5, 2026
Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
October 5, 2026
How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs
October 5, 2026
BT’s TalkTalk Rescue Turns Telecom Continuity Into a New Merger-Control Ground
October 5, 2026
Google Stops Accepting Product Bug Reports for Its Open-Source Bounty, Citing Automated Submissions

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A customer-support representative wearing a headset against a dark studio background.
Articles

The Meta AI Support Hack Was a Plain Old Authorization Failure

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026