Apple to tighten macOS Full Disk Access as autonomous AI agents raise risk
In short
Apple said it will tighten macOS’s “Full Disk Access” permission, so apps can obtain it only through a more explicit user action, because AI agents that operate a computer autonomously raise the risk of exposing personal data. The company has not published the specific measures or their timing. The change follows a privacy dispute over Meta’s Mac agent Muse, which Meta denies, and other reports of AI agent security flaws.
Read the full story 2 min read
Apple said it will add stricter controls to the “Full Disk Access” permission in future versions of macOS, so that apps can obtain it only after a more explicit action by the user. The company said the permission, which lets software reach files, mail, messages and browsing history, carries rising risk now that AI agents can operate a computer on their own. Landian reported Apple has not published the specific measures or their implementation date. [ 1 , 2 , 3 ]
According to Apple’s developer note, the permission was originally created so software such as backup tools could work, and Apple says some developers have used it in ways that may put users at risk without their fully understanding what they are granting. Huxiu reported the permission was introduced with macOS Mojave 10.14 and lets antivirus and backup software traverse the file system. Landian noted it is separate from FileVault encryption and that an authorised app can reach mail, messages, browser history and some system management settings. [ 1 , 2 , 3 ]
Apple said the risk grows because AI agents differ from traditional apps: instead of performing one fixed function, an agent can read files, analyse mail and messages and call other tools in sequence. The company warned that a communications app that misuses the permission could expose not only the device owner’s information but also the privacy of the people they communicate with. [ 1 , 2 ]
Landian reported that Apple will add new APIs to give finer-grained control, but that the company has not said whether it will introduce permissions split by folder or data type, periodic re-confirmation, separate limits for AI apps, or automatic revocation of permissions that go unused. [ 2 ]
The change follows a series of incidents involving Mac AI agents. cnBeta reported that journalist Jason Aten said Meta’s Mac agent Muse could read his private messages although he believed he had not granted the permission, and that Meta denied Muse can read Messages without authorisation, saying the feature is opt-in and requires both Full Disk Access and the Messages connector. Huxiu reported that technology blogger Matt Robb said Muse sent his home address to a buyer without consent, and cited a Salt Security finding that an email-injection flaw could let attackers manipulate the Manus Agent to obtain Gmail credentials. cnBeta also noted earlier reports of a vulnerability in the Mac version of ChatGPT and Apple’s WWDC presentation of a security architecture for Xcode and AI coding agents. [ 1 , 3 ]
Apple did not name any app, and cnBeta reported the tightening does not mean Apple concluded Muse had bypassed macOS security. Apple said its aim is not to stop users from granting broad permissions, but to ensure those who do so act deliberately and understand the privacy risk. [ 1 , 2 ]
Huxiu said Apple published the announcement on October 2 and reported that developer John Gruber is concerned the tighter controls will affect his app, which depends on the permission. The outlet argued that demand for always-on personal agents may shrink once the current wave passes, while the tightened system permissions are unlikely to be reversed. [ 3 ]
Why it matters
The change affects Mac users and any developer whose app depends on broad file access, and it signals that operating-system makers are reworking permission models for software that acts on a user’s behalf rather than performing a single task. Huxiu argued the tightened system permissions are unlikely to be reversed. Because the documents say no implementation date has been given, the practical impact on users and developers is not yet known.
Key facts
- Apple said it will add stricter controls to macOS’s Full Disk Access permission, so that apps can obtain it only through a more explicit user action. [ 1 , 2 , 3 ]
- Full Disk Access lets an app reach large amounts of data on a Mac, including files, mail, messages and browsing history. [ 1 , 2 ]
- Apple said the risk from the permission rises as AI agents become more powerful and more autonomous, and it did not name any app as a violator. [ 1 , 2 ]
- Apple has not published the specific changes or an implementation timetable; Landian reported new APIs will be added to refine permission control. [ 1 , 2 ]
- Landian reported Apple has not said whether it will add per-folder or per-data-type permissions, periodic re-confirmation, separate limits for AI apps, or automatic revocation of unused permissions. [ 2 ]
- A dispute over Meta’s Mac AI agent Muse preceded the change: a journalist said Muse read his private messages without permission, and Meta denied that Muse can read Messages without user authorisation. [ 1 ]
- Huxiu reported the announcement was published on October 2 and cited a Salt Security finding that an email-injection flaw could let attackers manipulate the Manus Agent to obtain Gmail credentials. [ 3 ]
- Developer John Gruber said he is concerned the tighter controls will affect his app, which relies on the permission, Huxiu reported. [ 3 ]
Confirmed by several sources
- Apple announced it will tighten macOS Full Disk Access controls, requiring more explicit user authorisation. [ 1 , 2 , 3 ]
- Apple said the permission exposes large amounts of user data, including mail, messages and browsing history. [ 1 , 2 ]
- Apple said the risk from the permission increases as AI agents become more capable and autonomous. [ 1 , 2 , 3 ]
- Apple has not disclosed the specific measures or when they take effect. [ 1 , 2 ]
Still unclear
- What the new controls will look like in practice. Landian reported Apple has not said whether it will introduce per-folder or per-data-type permissions, periodic re-confirmation, AI-specific limits or automatic revocation, and no document carries the final rules.
- Whether the tightening was prompted by the Muse case. cnBeta reported Apple’s move does not mean it found that Muse bypassed macOS security, and Landian reported Apple did not name any app.
- Whether Muse read Messages without authorisation. Only cnBeta carried both the journalist’s claim and Meta’s denial; no other document resolves the disagreement.
- Salt Security’s finding on the Manus Agent. Reported only by Huxiu, with no other document confirming it.
- Whether apps that already rely on the permission, such as John Gruber’s, will be affected. Huxiu reported his concern, but no document states the outcome for existing apps.
What local media are saying
Timeline, local time
- Apple publishes the announcement on tightening Full Disk Access, according to Huxiu. [ 3 ]
- cnBeta reports the change and the Muse privacy dispute, including Meta’s denial. [ 1 ]
- Landian reports Apple’s announcement and says the specifics and timing have not been published. [ 2 ]
- Huxiu publishes its analysis, citing the Salt Security finding and developer reaction. [ 3 ]