Apple will add controls requiring Mac users to take “very explicit user action” before granting an app Full Disk Access, citing growing risks from AI agents. The permission “largely sidesteps” macOS privacy controls to let backup apps work and can expose files, mail, messages and browsing history. For communication apps, that access can also compromise the privacy of people exchanging messages with the user, Apple said.
The company announced the change on Friday, Oct. 2. It gave no rollout date, macOS version or description of the controls, and named no app or developer. Apple declined to comment beyond its post.
What Changed
- Apple will require "very explicit user action" before a Mac app gets Full Disk Access, citing the growing risks from AI agents.
- Apple gave no rollout date, macOS version or description of the controls, and named no app or developer.
- About two weeks earlier, Inc. columnist Jason Aten said Meta's Muse referenced a private Messages thread; Meta says Muse needs both Full Disk Access and its Messages connector.
- Mac writers John Voorhees and John Gruber worry the controls could hamper utilities that are not backup apps.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
The Muse permissions dispute
About two weeks earlier, Inc. columnist Jason Aten said Meta’s Muse AI agent had referenced a private Apple Messages conversation with a co-worker in an unsolicited notification. He said he had never given the assistant permission to read his messages. Meta disputes his account.
“You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content,” Meta spokesperson Andy Stone wrote on X. “It can’t read your Messages unless you do this. And it can be revoked at any time.”
FREE AI BRIEFING · WEEKDAYS
Track what AI agents can reach on your devices.
Get the AI stories shaping the day, with concise context from San Francisco. The briefing takes about five minutes and arrives at 4:45 a.m. Pacific, 7:45 a.m. Eastern.
Free. No hype. Unsubscribe anytime.
Patrick Wardle, a software analyst at the Objective-See Foundation and longtime macOS researcher, questioned Meta’s assertion, saying Full Disk Access by itself makes any non-root file readable. “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc,” he told Ars Technica.
Other agent security findings
On Sept. 21, Wardle disclosed a Muse configuration that allowed any app or code already running on a Mac to take control of the assistant. That included commands introduced through ClickFix attacks. An attacker could then reach the resources available to Muse.
On Sept. 25, OpenAI acknowledged a flaw in its ChatGPT Mac app and its fix in its system change log. Researchers at Wardle’s organization, the Objective-See Foundation, found the flaw. Exploiting it required malware already installed on the machine. Wardle called it “insanely trivial” to exploit; his proof of concept needed about a dozen lines of code.
Wardle also found a now-patched flaw in Muse’s dictation feature that could let a local attacker obtain a mishandled authentication token and access user data.
Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.
Mac utilities depend on access
John Voorhees of MacStories called Apple’s backup-apps framing “nonsense.” Apps holding Full Disk Access on his MacBook Pro included the Finder replacement Bloom, Alfred, PopClip, Apple’s own Pixelmator Pro and Hazel. He said Apple’s concerns about agents were well-founded, while worrying that the controls, which Apple had not yet described, might restrict which kinds of apps could use the permission.
John Gruber of Daring Fireball also expressed concern about how far Apple would lock down access. Several apps he uses “couldn’t function properly without it,” he wrote. He worried that, under the controls Apple had not yet described, requiring authorization every time they acted would severely hamper them.
Gruber estimated the worldwide Mac user base at around 150 million and wrote that most were “unsophisticated technically.” Many, he wrote, assume Apple protects them from dangerous permissions as it does on an iPhone, without understanding how much access they grant on a Mac.
“Apple needs to find a way enable reasonable customer protections without hamstringing the Mac’s utility,” Voorhees wrote.
Frequently Asked Questions
What is Full Disk Access on macOS?
It is a Mac permission that, in Apple's words, largely sidesteps macOS privacy controls so backup apps can work. An app holding it can reach files, mail, messages and browsing history. For communication apps, Apple says, it can also expose the privacy of the people a user exchanges messages with.
When will Apple's new Full Disk Access controls arrive?
Apple has not said. Its Oct. 2 developer post gave no rollout date, no macOS version and no description of the controls, beyond saying users will have to take very explicit action to grant the permission. Apple declined to comment beyond the post.
What does Meta's Muse have to do with the change?
Apple named no app. About two weeks before its post, Inc. columnist Jason Aten said Muse referenced a private Apple Messages conversation he never gave it permission to read. Meta spokesperson Andy Stone said Muse can read Messages only if users enable both Full Disk Access and its Messages connector. Researcher Patrick Wardle said Full Disk Access alone makes any non-root file readable.
Why are some Mac users worried about the change?
Many apps that are not backup tools use Full Disk Access. John Voorhees listed Bloom, Alfred, PopClip, Hazel and Apple's own Pixelmator Pro on his MacBook Pro and worried Apple might restrict which apps can use it. John Gruber worried that repeated manual authorization would hamper apps he relies on.
Have AI apps on the Mac had other security problems?
Yes. On Sept. 21, Wardle disclosed a Muse configuration that let any code running on a Mac take control of the assistant. On Sept. 25, OpenAI acknowledged a flaw in its ChatGPT Mac app, and its fix, in its change log. Wardle also found a now-patched flaw in Muse's dictation feature.
AI-generated summary, reviewed by an editor. More on our AI guidelines.



Free AI briefing · Weekdays
The AI stories that matter, sourced and explained.
Join the Morning Briefing. It goes out every weekday at 4:45 a.m. Pacific, with later sends for the East Coast, Berlin and Tokyo.
Free when you sign up: The Paperclip Compendium, our tested guide to running AI agents.
Free. Unsubscribe in one click.
IMPLICATOR