Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple to tighten macOS Full Disk Access controls due to AI agent risks.
Summary
Apple is enhancing macOS Full Disk Access (FDA) controls to mitigate risks posed by AI agents. Some developers have exploited FDA to access sensitive user data like messages and browsing history without full user awareness. The upcoming changes aim to ensure users explicitly consent to such deep system access, especially as AI agents become more capable.
Full text
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access Ravie LakshmananOct 05, 2026Vulnerability / Artificial Intelligence Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge and understanding," Apple said in a post. "For communication apps, this can also compromise the privacy of the people users are communicating with." Full Disk Access, accessed via Privacy & Security in the Settings app, was introduced by Apple in macOS Mojave (version 10.14), offers users greater control over which applications can access their entire system and data from apps like Mail, Messages, Safari, and Time Machine backups. Once the setting is enabled for an application, it allows that program to bypass certain security restrictions and read and write to system files that apps are typically restricted from accessing or modifying. This option is essential for apps, such as security tools and backup software, that require deep system access to function properly. Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action. It's currently not known when the new controls will be rolled out. "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple added. "We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy." Although Apple did not take any specific name, the development appears to be a response to a recent report about how Meta's Muse agentic tool accessed a journalist's private iMessages after they granted it Full Disk Access. Muse is advertised as a "personal AI agent" built along the lines of OpenClaw that runs on a dedicated Linux virtual machine on Meta's cloud. Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Access and have a Messages connector setting in Muse enabled. "The Messages integration in the Muse Mac app is opt in," Meta CTO David Singleton said. "Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled." Apple's announcement also comes weeks after security researcher Patrick Wardle demonstrated a proof-of-concept (PoC) exploit for a zero-day in Muse's Mac app called not-a-mused that allows any app or terminal command to obtain access to the token that authenticates users to their Muse account. The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said. "The concern is that Muse may have significantly broader access than ordinary local malware, making it a particularly useful target for privilege/access amplification." Specifically, a local attacker can exploit an undocumented setting named "endo_voyager_dictation_endpoint" without requiring any special privileges, allowing them to capture dictated audio and prompts, inject malicious prompts, and abuse the access Muse has been granted for other malicious actions. Wardle has also been acknowledged for reporting another vulnerability, tracked as CVE-2026-100754, impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app. These findings demonstrate how the privileged position enjoyed by agentic tools, the extensive data they collect, and their ability to interact with various parts of the operating system, like writing files to disk, accessing the mic and camera, creating calendar events, sending emails, and monitoring location, can expand the attack surface and open the door for an adversary to abuse this access and steal sensitive data. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE artificial intelligence, MacOS, Privacy, Vulnerability ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills
Indicators of Compromise
- cve — CVE-2026-100754