ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI information
Apple Tightens Full Disk Access: AI Agents Can Read an Entire Mac's Data

Apple Tightens Full Disk Access: AI Agents Can Read an Entire Mac's Data

AI information • Admin • • 12 views

Full Disk Access is at the center of this dispute. On October 2, 2026, Apple announced that it will change the Full Disk Access permission setting in macOS; according to Ars Technica's reporting the same day, the decision came after a debate over how much user data AI agents can read. Apple did not name Meta, Muse, or any specific app, and it did not confirm that any agent had read a user's messages.

The controversy began with tech columnist Jason Aten. He said Meta's general-purpose AI agent Muse sent him a proactive notification that quoted a thread from his conversations with a colleague in Apple Messages, and he said he had never authorized Muse to read his messages. The episode sparked extensive discussion on social media: an AI assistant holding permissions for calendars, email, messages, and shopping accounts is as useful as a chainsaw — and just as dangerous.

A system-level permission versus an in-app switch

Meta CTO David Singleton responded that Muse reading Messages requires two switches to be on at the same time: macOS's system-level Full Disk Access, and the Messages connector setting inside the Muse app — and that the connector is opt-in, turned on by the user.

macOS security expert Patrick Wardle pushed back: technically, an app that obtains Full Disk Access can read almost all non-root files, including browsing history, browser cookies, and chat logs, regardless of the connector switch. Meta's PR team only repeated Singleton's statement and did not answer the point directly.

Apple's statement and earlier risk findings

Apple said some developers' use of Full Disk Access can put users at risk, exposing everything on their systems — including files, email, messages, and even browsing history — without users knowing or fully understanding it; for communications apps, it can also endanger the privacy of both parties to a conversation. As AI agents become more capable and more autonomous, Apple said, the risks of this kind of access will grow substantially, and the company is committed to making sure users clearly understand the risks and make an informed decision before granting such access.

This is not the first time Muse's access has been flagged. Wardle previously disclosed a Muse configuration that could let any app or code on a Mac fully control the AI assistant — including commands injected through a ClickFix attack — and thereby reach the resources Muse can access. Amazon has also banned Muse from its platform, arguing that it should operate openly and respect service providers' decisions about whether to participate.

Review permissions before granting them to an agent

Full Disk Access is a long-standing permission designed for a few scenarios such as backup and antivirus software, and its granularity is the entire disk. In the age of AI agents, it looks more like a master key: an in-app switch cannot contain the reach of a system-level permission itself. Before granting this permission to agent-type apps, users should think through what the app can actually read; for apps already authorized, it is worth reviewing the permission list in System Settings regularly and turning off anything no longer needed.

Recommended Tools

More