14.4 C
London
Saturday, October 3, 2026
Home AI Apple changes full-disk access permissions to curb abuse from AI agents
apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents
Apple changes full-disk access permissions to curb abuse from AI agents

Apple changes full-disk access permissions to curb abuse from AI agents

3
0

Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories.

Friday’s announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill aw or other power tool. While potentially useful, they can do real damage if not used carefully.

He said/she said

Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.

“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”

Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.

Earlier this week, I spoke to macOS security expert Patrick Wardle, who questioned Singleton’s denial. His reasoning: “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc.” I asked Meta how Muse couldn’t read messages when the app had full disk access, while every other app with that privilege could. Meta PR’s only response was to requote Singleton saying: “The Messages integration in the Muse Mac App is opt-in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”

Now, Apple is setting the record straight. In explaining why it was going to make changes to the FDA permission setting, the company wrote:

Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

The statement went on:

As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

Apple didn’t name Meta, Muse, or any other app or developer by name. Even though there are no known reports of other apps abusing FDA to read messages and browsing history, it’s certainly possible Friday’s statement wasn’t referring to the Muse incident. Then again, the timing of the announcement—coming on the heels of a major social media uproar—makes the possibility likely. And at a minimum, Apple’s statements seem to contradict Singleton’s denial that it’s not possible for Muse to read Messages content without the connector enabled. Meta PR didn’t respond to questions sent Friday.

Apple’s announcement came 11 days after Wardle disclosed a Muse configuration that allowed any app or code running on a Mac—including commands injected through the increasingly effective ClickFix attacks—to take full control of the AI assistant. From there, the attacker could access the same resources Muse could. It also comes after Amazon blocked Muse from its platform because, Amazon said, all such apps “should operate openly and respect service provider decisions about whether or not to participate.”

Taken together, the events suggest that Muse may not be worthy of the extraordinary access it must have to work as billed by Meta. People who use the assistant should configure permissions carefully, though as Aten’s experience suggests, that precaution only goes so far.