Apple to Tighten macOS Full Disk Access for AI Agents
AI-generated image

Apple to Tighten macOS Full Disk Access for AI Agents

Apple plans stricter macOS Full Disk Access controls after AI agents were shown exposing private messages and files without clear consent.

Apple is preparing to restrict macOS Full Disk Access, a powerful privacy setting, after warning that some AI agents are using it in ways that expose far more personal data than users realize. The company said it plans to update the control so that this kind of deep system access is granted only after an explicit user action, because the current setup can let applications read files, mail, messages, and even browsing history without users' full knowledge.

The Full Disk Access setting was introduced in macOS Mojave, version 10.14. It is found under Privacy & Security in System Settings, and it gives users control over which programs can reach protected data from Mail, Messages, Safari, and Time Machine backups. When switched on for an app, that app can bypass ordinary restrictions and read and write system files that other programs normally cannot touch. This level of access is essential for legitimate tools such as security scanners and backup software, which need deep visibility to do their jobs. But the same power is dangerous if it falls into the hands of software that users do not understand or that can be compromised.

Apple said the setting largely bypasses the privacy controls meant to protect private data, and that as AI agents become more capable and autonomous, the risks associated with this level of access will grow substantially. The company added that it is committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy. Apple did not give a date for when the new controls will be rolled out. The company did not name any specific app, but the announcement appears to follow a recent report about Meta's Muse agentic tool.

Muse is advertised as a personal AI agent built along the lines of OpenClaw, and it runs on a dedicated Linux virtual machine in Meta's cloud. According to the report, Muse accessed a journalist's private iMessages after the journalist granted it Full Disk Access. Meta has since clarified that for Muse to be able to read a user's private messages, two permissions must both be active: the macOS Full Disk Access setting must be granted, and a Messages connector inside Muse must be enabled. Meta CTO David Singleton said the Messages integration in the Muse Mac app is opt-in, and Muse can only read Messages content if the system-level permission and the connector are both turned on. This distinction matters because it shows that Full Disk Access alone is not enough for Muse to read messages; a separate in-app setting must also be switched on.

The timing of Apple's change also follows research by security researcher Patrick Wardle, who demonstrated a proof-of-concept exploit for a zero-day in the Muse Mac app. The exploit, named not-a-mused, allowed any app or terminal command to obtain the token that authenticates a user to their Muse account. Meta has since patched that vulnerability. Wardle explained that the flaw let an unprivileged local process redirect Muse's dictation traffic and abuse the trust and access already granted to the app. Because Muse may have far broader access than ordinary local malware, it becomes a particularly useful target for privilege and access amplification. The exploit used an undocumented setting called endo_voyager_dictation_endpoint, which required no special privileges. With it, a local attacker could capture dictated audio and prompts, inject malicious prompts, and misuse the access Muse had been granted for other harmful actions. In other words, a malicious program on the same Mac could hijack the AI assistant's permissions and use them to reach private data.

Wardle has also been credited with reporting another vulnerability, tracked as CVE-2026-100754, in OpenAI's ChatGPT app for Mac. That flaw could have been abused to take over the AI assistant and give an attacker unauthorized access to chat logs and other data stored by the app. The source does not state whether a patch for this issue has been released.

These findings show how agentic tools hold a privileged position, collect extensive data, and can interact with many parts of the operating system, including writing files to disk, using the microphone and camera, creating calendar events, sending emails, and monitoring location. That broad reach expands the attack surface and creates opportunities for an adversary to abuse the access and steal sensitive data. For businesses and IT teams, the change is a reminder that broad permissions can turn a useful automation tool into a risk. If an AI assistant with Full Disk Access is later compromised, an attacker inherits that same access. The Muse exploit shows how a local attacker can redirect an AI app's traffic and then use its permissions, which is a form of privilege escalation. Organisations should treat AI agents like any other software with deep system access and apply least-privilege principles: grant only the permissions an app truly needs, and review those permissions regularly.

For organisations that manage macOS devices or run services alongside AI assistants, AEU-I's security-first IT and consulting can help review which applications actually need broad system access and pare back unnecessary permissions.

How to Protect Yourself

  1. Open System Settings, go to Privacy & Security and then Full Disk Access, and remove any app you do not absolutely trust, especially AI assistants.
  2. Only turn on Full Disk Access when an app asks for it and you understand why it needs to see all your files, mail, and messages.
  3. Inside any AI assistant, turn off optional connectors or integrations like Messages access unless you really use them.
  4. Keep your Mac and all apps updated, because updates deliver fixes like the one that patched the Muse vulnerability.
  5. If you have granted broad access in the past, review it once a month and revoke anything you no longer need.

Vulnerabilities & Fixes

  • CVE-2026-100754 CVE-2026-100754 is a vulnerability in OpenAI's ChatGPT app for Mac reported by Patrick Wardle that could let an attacker take over the assistant and access stored chat logs and other data, with no patch or mitigation specified in the source. View the fix & details →

Terms Explained

  • Full Disk Access A macOS privacy setting that lets a specific app read and change files throughout the computer, including messages and backups, when switched on.
  • AI agent A program that can act on a device with some independence, often by reading email, files, camera, or other apps to perform tasks.
  • virtual machine A software-based computer running inside another computer, used to host Meta's Muse in the cloud.
  • zero-day A security weakness that was unknown to the maker and had no fix available when it was first discovered or used.
  • proof-of-concept A small demonstration that a security problem is real and can be exploited, not a full attack.
  • token A digital key that proves an app or device is allowed to access an account without asking for the password again.
  • connector An optional bridge inside an app that allows it to read or use data from another service, such as Messages.
  • CVE Common Vulnerabilities and Exposures, a shared reference number assigned to a specific security vulnerability so researchers and users can find the same information.

Related AEU services