Apple has announced plans to introduce stricter controls around macOS's Full Disk Access setting, a system permission designed to facilitate backups but increasingly exploited by AI agents for broad data access. The move comes as AI applications become more autonomous and capable of controlling desktop functions, reading files, accessing messages, and monitoring browsing history. Apple characterized the current landscape as genuinely concerning, with some developers deploying Full Disk Access in ways that expose sensitive user data without adequate transparency or consent mechanisms.
The announcement follows two high-profile security incidents that exposed vulnerabilities in how AI applications interact with user systems. A journalist reported that Meta's Muse AI agent accessed their private messages without explicit permission, sparking questions about the integrity of desktop-based AI permissions. Separately, a vulnerability in OpenAI's ChatGPT macOS application revealed potential for hackers to exploit the app's access to sensitive information. While Meta disputed the journalist's claims about message access, the incidents galvanized attention around the permissions granted to AI tools running on personal computers.
Full Disk Access represents an extraordinarily permissive macOS setting—when enabled, it grants applications unrestricted access to files, email, messages, and browser history. Some AI agents, including Meta's Muse, offer Full Disk Access as an optional setting to enhance their capabilities. However, Apple found that developers are leveraging this permission in ways that could expose users' entire digital footprint without clear user understanding or affirmative consent. The company's developers blog statement acknowledged that some builders are utilizing Full Disk Access in potentially risky ways that put users at substantial danger.
Apple's response involves implementing new controls that will require users to take explicit, granular action before granting applications this level of system access. The company intends to ensure that only users who genuinely desire to provide an application with such extraordinary permissions can do so through highly visible and deliberate user action. Apple emphasized that as AI agents become increasingly autonomous and capable, the security risks tied to broad file access will multiply significantly. The company committed to making certain users comprehend these risks before making permission decisions, allowing them to make genuinely informed choices about their data and privacy.
Gist is a free AI reader for your browser, iPhone, and Android. Get concise summaries and key takeaways from any article or podcast.
Get Gist — Free