Apple changes full-disk access permissions to curb abuse from AI agents

Ars Technica News

Summary

Apple is tightening macOS full-disk access permissions to prevent third-party developers and AI agents from misusing them to read users' private Messages, following controversy over Meta's Muse AI agent apparently referencing private conversations. Meta maintains the access was opt-in, while macOS security experts dispute that claim.

<p>Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories.</p> <p>Friday's <a href="https://developer.apple.com/news/?id=p6zjojqw">announcement</a> comes two weeks after tech columnist Jason Aten <a href="https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202">said</a> that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.</p> <h2>He said/she said</h2> <p>Meta CTO David Singleton <a href="https://www.threads.com/@davidsingleton/post/DddI7WtG8ul">joined the fray</a> with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.</p><p><a href="https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/">Read full article</a></p> <p><a href="https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/#comments">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 10/03/26, 05:16 AM

# Apple changes full-disk access permissions to curb abuse from AI agents Source: [https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/](https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/) Apple says it is changing its macOS privacy settings to stop third\-party app developers from misusing them to access message histories\. Friday’s[announcement](https://developer.apple.com/news/?id=p6zjojqw)comes two weeks after tech columnist Jason Aten[said](https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202)that Meta’s new general\-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co\-worker over Apple Messages\. Aten said he never granted Muse permissions to read his messages and had assumed they were off\-limits\. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool\. While potentially useful, they can do real damage if not used carefully\. ## He said/she said Meta CTO David Singleton[joined the fray](https://www.threads.com/@davidsingleton/post/DddI7WtG8ul)with a rebuttal that appeared solid\. For Muse to access Apple Messages, a user must manually give it two privileges\. One is full\-disk access, a macOS system\-level permission\. The other is to enable a Messages connector setting in Muse\. “The Messages integration in the Muse Mac app is opt in,” Singleton said\. “Your Muse can only read Messages content if macOS system\-level Full Disk Access is granted and the Messages connector is enabled\.” Singleton’s implication was clear\. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame\. Earlier this week, I spoke to macOS security expert Patrick Wardle, who questioned Singleton’s denial\. His reasoning: “From a technical point of view, with FDA \(full\-disk access\), any \(non\-root file\), is readable, browsing history, browser cookies, chats, etc etc etc\.” I asked Meta how Muse couldn’t read messages when the app had full disk access, while every other app with that privilege could\. Meta PR’s only response was to requote Singleton saying: “The Messages integration in the Muse Mac App is opt\-in\. Your Muse can only read Messages content if macOS system\-level Full Disk Access is granted and the Messages connector is enabled\.”

Similar Articles

Apple will limit Mac disk access as AI agents ‘substantially’ increase risk

The Verge

Apple announced it will tighten macOS Full Disk Access permissions, requiring 'very explicit user action' for apps to gain sweeping system access, citing substantially increased risks as AI agents become more capable and autonomous. The change follows scrutiny over Meta's Muse AI reading users' Messages content.

Updates to Full Disk Access in macOS

Hacker News Top

Apple is introducing stricter controls over Full Disk Access in macOS as AI agents become more autonomous, requiring explicit user consent for apps that need extraordinary system access.