Apple says it is changing macOS privacy settings to reduce the risk that third-party applications misuse Full Disk Access, a powerful system permission that can expose extensive personal data. Ars Technica reports that Apple announced the move on October 2, warning that increasingly capable AI agents make the consequences of broad access more serious.
The announcement followed controversy involving Meta's Muse assistant. Technology columnist Jason Aten said Muse sent him an unsolicited notification referring to an Apple Messages conversation between him and a coworker. Aten said he had not granted Muse permission to read his messages and believed that content was unavailable to the assistant.
Meta chief technology officer David Singleton responded that Muse's Messages integration is opt-in. According to his statement, a user must grant the Muse Mac application Full Disk Access at the macOS level and separately enable the Messages connector inside Muse before the assistant can read message content.

Security researcher Patrick Wardle challenged the technical implication of that explanation. He told Ars Technica that an application with Full Disk Access can read non-root files, including browser history, cookies and chats. When Ars asked Meta why Muse would be unable to read messages with that broad permission, Meta repeated Singleton's statement about the connector and Full Disk Access requirements.
Apple did not name Meta, Muse or any other developer. Its statement said some developers use Full Disk Access in ways that may expose files, mail, messages and browsing history without users fully understanding the consequences. Apple added that communication data can also compromise the privacy of other people involved in those conversations.
The company said the danger will increase as AI agents become more capable and autonomous, and that users need clearer information before granting such access. Ars Technica's report does not specify the exact interface changes Apple plans to make or when they will reach users, so the practical scope of the update remains uncertain.

The dispute highlights a mismatch between narrow-looking product controls and broad operating-system privileges. A connector switch may communicate what a developer intends an agent to use, while Full Disk Access determines what the application can technically reach. Apple's intervention suggests that user understanding cannot depend only on settings inside the app receiving the permission.
Ars also connects the announcement to an earlier finding from Wardle. Eleven days before Apple's statement, he disclosed a Muse configuration that could let other applications or code running on a Mac take control of the assistant, including commands delivered through ClickFix attacks. An attacker could then reach resources available to Muse. Amazon later blocked Muse from its platform, saying such applications should respect service providers' participation decisions.
Apple's timing makes a connection to the Muse controversy plausible, but the company did not confirm that the incident prompted its action. Ars notes that no other applications are publicly known to have abused Full Disk Access to read messages or browsing history. The broader warning nevertheless applies to any autonomous software operating with the same permission.
For users, careful permission choices remain important but may not be sufficient when one approval unlocks many categories of information. The people whose messages appear on a device may also be exposed even though they never approved the agent. Apple's planned changes are an acknowledgment that traditional permission models need clearer boundaries as software shifts from passive tools to systems that can independently inspect data and act on it.

Comments
Loading comments…