Apple tightens macOS Full Disk Access over AI agent risks
TECH

Apple tightens macOS Full Disk Access over AI agent risks

41+
Signals

Strategic Overview

  • 01.
    Apple announced on October 2, 2026 that it will tighten macOS's Full Disk Access permission, requiring more explicit user action before an app can be granted it, explicitly citing the growing autonomy and capability of AI agents as the reason for the change.
  • 02.
    The announcement follows a disputed incident in which columnist Jason Aten reported that Meta's Muse AI agent referenced private iMessage content even though Full Disk Access appeared switched off, and found that Muse had synced his Messages database up to row 187,462. Meta disputes the account: spokesperson Andy Stone said Messages access requires two user-controlled permission steps, while Meta Superintelligence Labs lead David Singleton described three separate permission steps.
  • 03.
    Separately, security researcher Patrick Wardle published a proof-of-concept showing an undocumented Muse Mac app preference could let malware already running as the logged-in user turn the agent into a backdoor, redirecting dictation and capturing authentication tokens.
  • 04.
    Apple did not provide a technical breakdown of how the new Full Disk Access controls will work or when they will arrive, and the permission was originally designed largely to let backup apps work around macOS's normal privacy controls.

A Permission Built for Backups, Repurposed for Agents

Full Disk Access was originally created largely as an exception for backup software, letting it work around macOS's normal privacy controls [6]. That history matters now because the permission is extremely broad by design: security researcher Patrick Wardle notes it grants read access to effectively any non-root file on a Mac, including Messages chat databases, browser cookies, and browsing history [2]. Apple's own language acknowledges the mismatch between that original purpose and how it is used today: "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems - including files, mail, messages, and even browsing history - without users' full knowledge and understanding" [1]. The company frames this as a structural problem that will only get worse, warning that "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially" [1].

The Disputed Incident That Forced Apple's Hand

The immediate trigger for Apple's announcement traces back to a single contested story. Columnist Jason Aten reported that after installing Meta's Muse on his iPhone and Mac mini, the agent referenced private Messages content - including a column idea drawn from a conversation with his podcast co-host - even though Full Disk Access appeared switched off in System Settings; he later found Muse had synced his Messages database up to row 187,462 [3][4]. Meta disputed the account directly. Communications chief Andy Stone said "It can't read your Messages unless you do this," and Meta Superintelligence Labs lead David Singleton stated that "the Messages integration in the Muse Mac App is opt-in" and requires three separate permission steps that cannot be bypassed by macOS system protections [3]. Neither account has been independently verified, leaving an unresolved contradiction between a concrete, specific claim and a detailed technical denial.

A Separate, More Concrete Vulnerability

Distinct from the disputed Messages claim, Wardle's research describes a vulnerability that is independently demonstrated rather than contested. His proof-of-concept, published September 21, 2026, showed that an undocumented Muse Mac app preference called endo_voyager_dictation_endpoint could let malware already running as the logged-in user redirect dictation, read what a user dictates, inject trusted instructions, and capture authentication tokens, something he described as making it "trivial to turn Muse into the ultimate backdoor" [2]. Wardle is careful to scope the risk: the flaw "only works if an attacker can already run code as the logged-in user. It cannot break into a Mac on its own," though it could be chained with social-engineering tricks [2]. Apple's announcement arrives alongside a separately reported flaw in OpenAI's ChatGPT Mac app that could have let attackers reach sensitive data before OpenAI fixed it, suggesting the company is responding to a pattern across AI desktop agents rather than one isolated product [5].

Why a UI Toggle Alone May Not Close the Gap

Even with Apple's stricter gating on granting Full Disk Access, the permission's underlying scope does not change - it still hands out read access to virtually all non-root files on the system [2]. The unresolved question underneath both the Muse dispute and Apple's fix is the same one: whether a single permission toggle, however explicit, is still a meaningful control once an agent is capable, autonomous, and already running with the user's own system privileges.

Historical Context

2026-07
Meta discontinued Muse Image after a separate privacy backlash over unauthorized Instagram account linkage.
2026-09-19
Jason Aten first reported that Muse appeared to access his private iMessage conversations despite Full Disk Access being switched off.
2026-09-21
Wardle released a proof-of-concept showing a hidden Muse Mac app dictation-endpoint setting could be abused as a backdoor by malware already running on the system.
2026-10-02
Apple announced via its developer news website that it will tighten Full Disk Access controls on macOS in response to AI agent risks.

Power Map

Key Players
Subject

Apple tightens macOS Full Disk Access over AI agent risks

AP

Apple

Platform owner of macOS; announced the Full Disk Access policy change and controls when/how it ships.

ME

Meta (Muse AI agent / Meta Superintelligence Labs)

Developer of the Muse personal AI agent at the center of the private-Messages access dispute; disputes the journalist's account via spokesperson Andy Stone and Meta Superintelligence Labs lead David Singleton.

JA

Jason Aten

Inc. columnist who reported that Muse appeared to reference his private iMessage conversations despite declining the relevant permission, triggering the scrutiny that preceded Apple's announcement.

PA

Patrick Wardle

macOS security researcher who published a proof-of-concept showing a hidden Muse Mac app setting could be abused as a backdoor, and who noted Full Disk Access alone grants read access to effectively any non-root file.

OP

OpenAI

Developer of the ChatGPT Mac app, which was reported to have had a flaw potentially letting attackers reach sensitive data; cited as part of the broader backdrop for Apple's decision.

Fact Check

6 cited
  1. [1] Apple Announces macOS Full Disk Access Changes
  2. [2] One Hidden Meta Muse Setting Could Let Malware Turn It Into a Backdoor
  3. [3] Meta Denies Muse Accessed Jason Aten's Private Messages
  4. [4] Meta's Muse AI Agent Accused of Accessing Sensitive User Data Without Permission
  5. [5] Apple Says It's Tightening macOS Full Disk Access Controls Due to New Risks From AI Agents
  6. [6] Apple Tightens macOS Full Disk Access Controls as AI Agents Substantially Increase Risk

Source Articles

Top 5

THE SIGNAL.

Analysts

“Argues that Full Disk Access grants read access to effectively any non-root file on a Mac, including Messages chat databases, browser cookies, and browsing history, undermining claims that a secondary in-app toggle is a meaningful safeguard; also demonstrated that an undocumented Muse preference could be abused as a backdoor.”

Patrick Wardle
macOS security researcher

“Defends Muse's design, stating Messages access is opt-in and gated behind three separate permission steps plus macOS system protections that cannot be circumvented by app bugs.”

David Singleton
Lead, Meta Superintelligence Labs

“Pushed back publicly on Aten's claim, insisting Muse cannot read Messages without the user actively enabling both Full Disk Access and the in-app Messages connector.”

Andy Stone
Meta Communications Chief
The Crowd

“Apple announced it will tighten "full disk access" in macOS. This permission, which can read emails, messages, and even browsing history in full, was originally an exception meant for backups, but AI agents have started using it. Meta explained that "three levels of permission are required and cannot be bypassed," but in the end, iMessage permissions that users had denied were being enabled without their consent. We've reached a stage where simply trusting the developers' explanations isn't enough to stay protected.”

@@joho_no_todai152

“An AI agent reportedly pulled 187,000+ rows from an Apple Messages database. User says he never knowingly gave it access. Meta says Muse can't access Messages without explicit permission. Now Apple is adding more controls around Full Disk Access. Pretty simple problem: if I need a PhD to figure out what my AI agent can read, the permissions are cooked.”

@@nordin_eth71

“Check 3 Mac permissions to see if Meta's Muse agent is allowed into your private messages. Meta says it takes three: Full Disk Access, a Messages access level, a macOS confirm that restarts the app. First one off, message options stay grayed out. Journalist Jason Aten says his was off and Muse cited his messages anyway. Neither side is independently verified. Meta itself counts 2 toggles or 3 steps. The 3 steps below.”

@@Joyingeth34

“Apple sounds the alarm on AI agents and 'Full Disk Access'”

@u/efap17011700
Broadcast
Meta Muse is SCARY… This AI Wants to Know Everything About You!

Meta Muse is SCARY… This AI Wants to Know Everything About You!

Meta Muse AI Agent Violates User Privacy - Zuckerberg Doesn't Take "No" as an Answer

Meta Muse AI Agent Violates User Privacy - Zuckerberg Doesn't Take "No" as an Answer

Muse AI Privacy Warning: A User Says It Read His Messages

Muse AI Privacy Warning: A User Says It Read His Messages

Apple tightens macOS Full Disk Access over AI agent risks — AI News | Agentic Brew