Application Security · AI-Powered Attack

Apple Tightens Full Disk Access for AI Agents

Apple said it is adding new controls to macOS Full Disk Access after reports that Meta’s Muse could surface private Messages content, and it is framing the change as a response to AI-agent risk rather than a single-app complaint. Meta says Muse still requires explicit user permissions, including Full Disk Access and the Messages connector, before it can read that data.

Full Disk Access is a broad macOS grant: Apple says it can let an app reach files, mail, messages, and browsing history. That means an assistant that also has an app connector can stitch together data a user may have thought of as separate, so the issue is the size of the permission boundary, not just the chat app involved.

For Mac environments that are piloting desktop assistants, the exposure sits in the consent model itself. If an AI agent can already act like a system-wide observer, a user-visible opt-in may not be a fine enough control to keep unrelated personal data from becoming visible at once.

2 sources · 2h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-02

Every edition of this story: Apple Tightens Full Disk Access for AI Agents