
Apple to Tighten macOS Full Disk Access Over AI Agent Security Risks
AI Summary
Apple is updating macOS privacy controls to limit 'Full Disk Access' after reports that AI agents like Meta's Muse could access private messages without clear user consent.
Apple announced it will restrict 'Full Disk Access' on macOS, requiring more explicit user actions to prevent third-party apps and AI agents from misusing system-wide permissions to read private data.
Apple is introducing new controls for its Full Disk Access (FDA) setting on macOS to ensure users only grant the permission through "very explicit user action." According to reports from TechCrunch and The Verge, the company stated that some developers are using the feature in ways that expose files, mail, and browsing history without the full understanding of the user. Apple noted that while the feature was originally designed for backup apps, the rise of autonomous AI agents has caused the risks associated with this level of access to "grow substantially."
The policy change follows a public dispute involving Meta’s AI agent, Muse. Columnist Jason Aten reported that the chatbot referenced a private message thread despite him not granting it explicit permission to read his messages. Meta CTO David Singleton and spokesperson Andy Stone both pushed back on the claim, stating that Muse can only read such content if a user manually enables both the macOS system-level FDA permission and a specific Messages connector within the Muse app. However, macOS security expert Patrick Wardle told Ars Technica that any app with FDA can technically read non-root files, including chat histories and cookies.
The decision to limit the feature also follows a separate report by Wired, cited by TechCrunch, regarding a flaw in the ChatGPT Mac app that could have permitted unauthorized access to sensitive data. Apple has not yet specified a date for when these updated controls will be rolled out to Mac users. In a blog post aimed at developers, the company emphasized that it is critical for users to clearly understand the risks of granting "extraordinary" system access as AI capabilities become more autonomous.
Background
Full Disk Access is a macOS security feature that allows specific applications to bypass standard privacy controls to access a user's entire system. It was primarily intended to allow backup software to function correctly by providing access to all files on the hard drive.
How outlets covered it
Image: TechCrunchTechCrunchApple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Image: The VergeThe VergeApple will limit Mac disk access as AI agents ‘substantially’ increase risk
Image: Ars Technica - All contentArs Technica - All contentApple changes full-disk access permissions to curb abuse from AI agents
Get our daily briefing first.
We're starting a short daily email with the stories most outlets are covering. Join the list to get the first one.
Free. No spam.
Discussion
No comments yet. Be the first to start the conversation!