Apple Says AI Agents Make Full Disk Access Too Risky. Its Fix Has No Date and Names No App.
On Friday, October 2, Apple posted a two-paragraph note to its developer news page titled "Updates to Full Disk Access in macOS." The short version: Mac apps will soon need what Apple calls "very explicit user action" before they can get the one permission that sees almost everything on the machine.
The reason Apple gave is not backup software. It is agents. "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," the post says.
What the post does not contain matters just as much. It names no app and no developer. It gives no macOS version. It gives no date.
What Apple Actually Said
Apple's own framing is blunt about the permission it built. Full Disk Access, the post says, "largely sidesteps" the privacy controls Apple gives developers, and exists so backup apps can work on the Mac.
Then it gets pointed. Apple says some developers are using Full Disk Access "in ways that could put users at risk," exposing files, mail, messages and "even browsing history" without users' "full knowledge and understanding." For communication apps, Apple adds, that can compromise the privacy of the people users are talking to.
The remedy is consent, not capability. Apple says it will "introduce additional controls" so that users who "genuinely wish" to grant an app this access can only do so with very explicit action. The Verge notes Apple did not say when the update ships, and Apple did not immediately respond to its request for comment.
| Question | Apple's October 2 post |
|---|---|
| What changes | "Additional controls" requiring "very explicit user action" |
| Why now | AI agents becoming more capable and autonomous |
| Which apps | None named |
| Which macOS version | Not stated |
| When | Not stated |
| Scoped alternative to the permission | Not mentioned |
The Two Weeks Before the Post
Apple did not say what prompted the note. The calendar around it is not subtle, and Ars Technica, The Verge and TechCrunch all read it against the same dispute.
On Saturday, September 19, Inc. columnist Jason Aten wrote that Meta's new Muse agent read his messages after he chose not to give it access. He had installed Muse on an iPhone and on a Mac mini he uses for testing. Muse then pitched him a column idea based on texts with a co-host. Asked how it knew, Muse said it saw only notification banners. Aten then found Muse had synced his Messages database up to row 187,462, while Muse's own settings showed Full Disk Access switched off.
One caveat Yahoo Tech flagged is worth keeping: a database row number is not necessarily a count of individual messages.
Meta's answer was that this could not happen without the user. "The Messages integration in the Muse Mac app is opt in," Meta Superintelligence Labs executive David Singleton said, as quoted by Ars Technica. "Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled." Singleton also said Muse gave Aten an incorrect explanation, and apologized for that. Meta spokesperson Andy Stone said access to Messages is "entirely opt-in."
Mac security researcher Patrick Wardle pushed back on the logic, not the toggles. He told Ars Technica: "From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc." In other words, once an app holds Full Disk Access, a per-app "connector" switch is a policy the app enforces on itself, not a wall macOS enforces for you.
| Date | Event |
|---|---|
| Sat Sep 19 | Aten's Inc. column: Muse synced Messages to row 187,462 with Full Disk Access shown off |
| Mon Sep 21 | Wardle discloses a Muse for Mac zero-day; Meta hot-fixes it |
| Fri Sep 25 | Fix for a separate ChatGPT Mac app flaw in production, per OpenAI's changelog as cited by Wired |
| Wed Sep 30 | TechCrunch reports Meta's dispute of Aten's account |
| Fri Oct 2 | Apple posts the Full Disk Access update; Wired reports the ChatGPT Mac flaw |
The Wardle disclosure came 11 days before Apple's post, by Ars Technica's count. As 9to5Mac described it, any app or Terminal command running locally could change undocumented Muse settings without special macOS permissions, including one that controls where dictated prompts are sent. Redirect that to your own server and you can grab the user's authentication token and drive the agent. Wardle's proof of concept wrote files, took photos with the camera and pulled a linked iPhone's location. It needed local code execution first, but a ClickFix-style trick that gets a user to paste a command into Terminal is enough. Meta patched quickly; Wardle's reply was "Hooray, hot-fixed!"
Meta was not alone. On the same Friday as Apple's post, Wired reported a flaw in OpenAI's ChatGPT app for macOS, found by researchers at the Objective-See Foundation, the Mac security nonprofit Wardle founded. Local code already running on the Mac could reach ChatGPT chat logs and capabilities tied to trusted ChatGPT components, including requests touching browser sessions. None of the reports we read cite confirmed exploitation. Amazon, for its part, has blocked Muse from its store, saying such apps "should operate openly and respect service provider decisions about whether or not to participate."
Why the Permission Is Wrong for Agents
Full Disk Access was designed for a backup app: software that reads everything, changes nothing, and does it for one narrow purpose. An agent is the opposite shape. It reads widely, acts on what it reads, talks to a cloud model, and takes instructions from content it did not write.
Give that software an all-or-nothing permission and every safety promise moves inside the app. Muse's Messages connector, an in-app approval gate, a "we only read banners" explanation: none of it is enforced by the operating system once the master key is granted. That is exactly the gap Wardle described and exactly the gap Apple's post concedes.
A more explicit consent screen narrows one failure mode, the user who clicked through without understanding. It does nothing for the user who understood and granted access anyway, and then had the agent hijacked through a local bug like the one Wardle found.
Our Take
Apple is right, and late, and vague. Right, because the post says out loud what researchers like Wardle have been saying: a desktop agent holding Full Disk Access can read everything, and its own toggles are only promises. Late, because Muse shipped on the Mac with this permission model already in place. Vague, because a change with no version, no date and no description of the new flow gives developers nothing to build against.
Our view is that friction is the wrong fix. Agents need a scoped permission, something like "this app may read Messages" or "this app may read Mail," enforced by macOS and revocable per data type, not a scarier version of a master key built for Time Machine alternatives. Apple already does per-category consent for photos, contacts and calendars. Messages and browsing history are the categories agents most want and users most fear losing.
There is also a platform tell here. Apple chose to publish this on its developer news page, not to a security advisory, and to frame it as a developer behavior problem. Every third-party agent on the Mac now runs on a permission whose terms Apple can tighten unilaterally, on its own schedule. If you ship a desktop agent, plan for the day your onboarding flow gets one more scary dialog, and start asking yourself whether you need Full Disk Access at all.
Three signposts for the next 60 days. First, whether Apple ships the new control in a named macOS release, and whether it adds anything scoped rather than just a harder consent prompt. Second, whether Meta publishes a technical account of how Muse reached row 187,462 on Aten's Mac. Third, whether other desktop agent makers, OpenAI included, publish exactly which macOS permissions their apps request and why.
For more on the Muse product line, see our coverage of Muse Glimmer, and for the last time a permission promise broke across several agents at once, see Plugin4Shell.
Sources: Apple Developer, Updates to Full Disk Access in macOS, TechCrunch, Ars Technica, The Verge, Jason Aten at Inc., The Next Web, Yahoo Tech, TechCrunch on Meta's denial, 9to5Mac on the Muse zero-day, Wired on the ChatGPT Mac flaw, and TechSpot on Amazon's Muse block.
