Apple tightens macOS full-disk access rules
Apple is changing a macOS privacy setting after an AI agent read a columnist's messages, raising questions about third-party app permissions.
Apple is moving to restrict how third-party developers can use a powerful macOS privacy setting, after a prominent tech columnist said Meta's new AI assistant read his messages without his permission. The change targets Full Disk Access, a system-level permission that lets apps read files and data across a Mac, and it follows weeks of online backlash over what an AI agent could see once granted that privilege.
According to Ars Technica's reporting, Apple said it will alter the Full Disk Access setting because some developers are using it in ways that expose far more user data than people realize. The company's statement did not name Meta or its assistant, but it arrived two weeks after columnist Jason Aten said Meta's general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permission to read his messages and had assumed they were off-limits.
The incident set off a wave of social media reaction from users who said AI assistants with access to calendars, emails, messages, and shopping accounts are like power tools: useful, but capable of real damage if not handled carefully. Apple's response, announced on a Friday, effectively sets new rules for how that access is granted.
What Apple actually changed
Apple's announcement centered on Full Disk Access, a macOS permission that gives an app broad reach across a user's system. In explaining the change, the company wrote that "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding." Apple added that for communication apps, the setting "can also compromise the privacy of the people users are communicating with."
The company also framed the move as a response to a broader trend: AI agents that are "increasingly capable and autonomous." In its statement, Apple said "the risks associated with this level of access will grow substantially," and that it is "committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy."
Apple did not name Meta, Muse, or any other app or developer in its announcement. There are no known reports of other apps abusing Full Disk Access to read messages and browsing history, so it's possible the statement was not aimed at the Muse incident. Still, the timing—coming on the heels of the social media uproar—makes that possibility likely, and Apple's language at a minimum appears to contradict Meta's earlier denial that Muse could read Messages content without a separate connector enabled.
The dispute over Muse's access
Meta CTO David Singleton had previously pushed back on the idea that Muse could read messages without deliberate user action. He said that for Muse to access Apple Messages, a user must manually grant two privileges: Full Disk Access at the macOS level, and the Messages connector setting inside Muse.
"The Messages integration in the Muse Mac app is opt in," Singleton said. "Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled."
— David Singleton, CTO at Meta
Singleton's implication was that Muse could have read Aten's Messages communications only if he had enabled both settings—and that if he had, the columnist had only himself to blame, not Meta. The company repeated that position when pressed. Ars Technica reported that when it asked Meta how Muse couldn't read messages when the app had full disk access, while every other app with that privilege could, Meta PR's only response was to requote Singleton's line about the integration being opt-in.
But macOS security expert Patrick Wardle questioned that denial. His reasoning, as quoted in the Ars Technica report: "From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc." Wardle's point was that Full Disk Access is not a narrow permission—it is a broad one, and any app holding it can read the same categories of data as any other app holding it.
A separate Muse configuration problem
The permission debate was not the only issue to surface around Muse. According to Ars Technica, Apple's announcement came 11 days after Wardle disclosed a Muse configuration that allowed any app or code running on a Mac—including commands injected through ClickFix attacks—to take full control of the AI assistant. From there, an attacker could reach the same resources Muse itself could access.
That disclosure added a second layer to the concern: even users who carefully configure Muse's permissions could still be exposed if another piece of software on the same Mac can seize control of the assistant. ClickFix attacks, which rely on tricking users into running malicious commands, were cited as one route into that configuration.
Ars Technica also reported that Amazon blocked Muse from its platform. Amazon's stated reason was that all such apps "should operate openly and respect service provider decisions about whether or not to participate." The block came as part of the same broader sequence of events around Muse's reach and behavior.
Why Full Disk Access is so sensitive
Full Disk Access sits at the top of macOS's privacy hierarchy. It is not a per-folder or per-file permission; it is a system-level grant that lets an app read data that would otherwise be shielded by macOS's protections. That includes mail, messages, browsing history, browser cookies, and chats, as Wardle described. For an AI assistant that needs to work across a user's apps, that kind of access can look necessary—but it also means a single misconfigured or compromised assistant can see a wide slice of a user's digital life.
Apple's statement acknowledged that tension directly. The company said it wants users to understand the risks before granting access, rather than discovering afterward what an app could read. The change is aimed at making that grant less of a blanket permission and more of an informed decision.
The dispute between Meta and critics like Wardle comes down to a technical question: does a separate in-app connector setting meaningfully restrict what Muse can read, or does Full Disk Access override that restriction by making the underlying data readable regardless? Wardle's position is that at the operating-system level, Full Disk Access makes the files readable, full stop. Meta's position is that the connector is what gates Messages content. Apple's announcement did not resolve that dispute by naming names, but its description of how Full Disk Access can expose messages suggests the OS-level permission is the more consequential control.
The social media reaction
The initial report from Aten drew widespread agreement online. Users said the episode showed that AI assistants granted access to calendars, emails, messages, and shopping accounts behave like power tools—capable of doing real work but also capable of causing real harm if not used carefully. The comparison framed the debate less as a bug and more as a question of how much trust users should place in an agent that sits across their personal communications.
Meta's CTO entered the discussion directly with the rebuttal that the Messages integration is opt-in and requires two separate grants. That response was widely circulated, but it did not end the argument. Wardle's technical objection, and the later disclosure of a configuration that let other code take over Muse, kept the question open. By the time Apple weighed in, the conversation had moved from a single columnist's experience to a broader examination of what AI agents are permitted to see on a Mac.
What Apple left unsaid
Apple's announcement is notable for what it does not contain. The company did not name Meta, Muse, or any other developer. It did not describe a specific incident. It did not say whether its change was prompted by the Muse episode or by a broader review of how developers use Full Disk Access.
That silence leaves room for interpretation. Because there are no known reports of other apps abusing Full Disk Access to read messages and browsing history, it is possible Apple was reacting to a general risk rather than a specific one. But the timing—two weeks after Aten's report, and 11 days after Wardle's disclosure—makes a connection to the Muse case plausible. At a minimum, Apple's description of Full Disk Access as a permission that can expose "files, mail, messages, and even browsing history" without users' full knowledge aligns with the concerns raised about Muse.
Meta did not respond to Ars Technica's questions sent on the Friday of Apple's announcement, according to the report. That left Singleton's earlier statement as the company's most recent public position on the matter.
The bigger question for AI agents
The Muse episode has become a case study in a problem that extends well beyond one app. AI agents are designed to act across a user's data—reading messages, checking calendars, drafting emails—and that usefulness depends on access. But the same access that makes an agent helpful also makes it a high-value target and a potential source of unintended exposure. Apple's statement pointed to this directly, saying that as AI agents become more capable and autonomous, the risks of broad access will grow.
For users, the practical takeaway is that permission grants are not interchangeable. Full Disk Access is a system-level key, and an agent that holds it can reach data that a narrower permission would protect. Aten's experience suggests that even users who believe they have not granted a permission may find an assistant referencing content they thought was private. The dispute between Meta and Wardle is ultimately about whether that can happen without the connector—and Apple's move suggests the operating system's own permission is the one that matters most.
For developers, Apple's change is a signal that Full Disk Access will face more scrutiny. The company said it wants users to understand risks before granting access, which could mean clearer prompts, more explicit descriptions of what an app will read, or additional friction before the permission is enabled.
For the AI assistant industry, the episode raises a question that Apple's statement only hints at: how much access should an autonomous agent have by default, and who is responsible when that access is misused? Apple's answer, so far, is to make the permission harder to grant without understanding it. That does not resolve the Meta dispute, and it does not guarantee that a carefully configured assistant is safe from other code on the same machine. But it does indicate that the company sees broad disk access for AI agents as a risk worth addressing at the operating-system level.
Sources
- Ars Technica Original source
Continue Reading
MI5: MSS Front Funded 100+ Academics
The alert urges U.K. universities to review CGTRI ties, warning that continuing collaboration could lead to prosecution.
Fortra BoKS Patches Fix Critical Auth Bypass
Fortra fixed eight bugs in BoKS, including a 9.9-severity auth bypass and a 9.1 command injection, but reported no known exploitation.
Sanders bill targets federal Flock use
Sen. Bernie Sanders introduced the Ban Flock Act to bar federal agencies from using license plate readers or accessing their data.