Apple tightens macOS full disk access controls for AI agents
Apple plans stricter controls for macOS Full Disk Access to mitigate privacy risks from autonomous AI agents, following recent security vulnerabilities in Meta and OpenAI apps.
Apple has announced plans to tighten security controls around the macOS Full Disk Access permission, citing growing risks posed by autonomous artificial intelligence agents. The move comes in response to recent incidents where AI tools accessed private user data, prompting the company to ensure users explicitly understand the implications of granting such broad system privileges.
What happened
Apple stated that some developers are utilizing Full Disk Access in ways that expose users to significant privacy risks. This permission allows applications to read and write to nearly every part of the system, including files, email, messages, and browsing history, often without the user fully grasping the extent of the exposure. For communication apps, this broad access can also compromise the privacy of third parties who are communicating with the user.
The announcement appears to be a direct response to reports involving Meta’s Muse, an agentic tool that accessed a journalist’s private iMessages after being granted Full Disk Access. While Meta clarified that its Messages integration is opt-in and requires both system-level access and an internal connector setting, the incident highlighted how easily sensitive data can be exposed when powerful AI agents are given deep system permissions. Apple emphasized that as AI agents become more capable and autonomous, the risks associated with this level of access will grow substantially.
In addition to the Meta incident, security researcher Patrick Wardle recently demonstrated vulnerabilities in popular AI applications. He revealed a zero-day exploit in the Muse Mac app, dubbed "not-a-mused," which allowed any local process or terminal command to access the authentication token for a user’s Muse account. Although patched, the vulnerability showed how an unprivileged local process could redirect dictation traffic and abuse the trust granted to the app. Wardle also reported CVE-2026-100754, a vulnerability in OpenAI’s ChatGPT Mac app that could have allowed attackers to take over the assistant and access chat logs.
How it works
Full Disk Access was introduced in macOS Mojave (version 10.14) to give users control over which applications can bypass standard sandboxing restrictions. When enabled, an app can read and modify system files and data from protected apps like Mail, Messages, Safari, and Time Machine backups. This level of access is essential for legitimate utilities such as backup software, antivirus tools, and system monitors that need to operate across the entire file system.
However, this permission effectively bypasses many of the operating system’s built-in privacy safeguards. Apple plans to update the mechanism to ensure that granting Full Disk Access requires a more explicit and informed user action. The goal is to prevent scenarios where users inadvertently grant sweeping permissions to AI agents that may not need such broad access to function, thereby reducing the attack surface for potential exploits.
Key details
- Apple plans to update Full Disk Access controls to require explicit user action for granting permissions.
- The change addresses risks from AI agents that can access files, mail, messages, and browsing history.
- Meta’s Muse tool previously accessed private iMessages after receiving Full Disk Access and enabling an internal connector.
- Security researcher Patrick Wardle found a zero-day in Muse called "not-a-mused" that exposed authentication tokens.
- Wardle also identified CVE-2026-100754 in OpenAI’s ChatGPT Mac app, which could allow unauthorized access to chat logs.
- The timeline for rolling out the new macOS controls has not yet been announced.
Why it matters
For software engineers and technical founders building AI-powered desktop applications, this shift signals a tighter regulatory and platform-specific environment for data access. Relying on Full Disk Access as a shortcut for data ingestion or context gathering will likely face higher friction from both the operating system and users. Developers must now justify deep system access more rigorously and design their agents to request only the minimum necessary permissions, aligning with the principle of least privilege.
The vulnerabilities found in Muse and ChatGPT illustrate that AI agents are high-value targets for attackers. Because these agents often have broad capabilities—such as sending emails, accessing microphones, or modifying calendars—a single vulnerability can lead to disproportionate damage. Security teams must treat AI integrations with the same scrutiny as core system components, ensuring that authentication tokens and data pipelines are hardened against local privilege escalation attacks.
What you can do
- Audit your application’s permission requests to ensure Full Disk Access is only used when absolutely necessary.
- Implement granular permission checks within your AI agent rather than relying solely on OS-level blanket access.
- Review authentication flows for AI services to prevent token leakage via local exploits or undocumented settings.
- Educate users clearly about what data their AI agent accesses and why, avoiding vague or misleading permission prompts.
- Monitor for security advisories related to AI frameworks and libraries you use, particularly those interacting with macOS APIs.
- Prepare for upcoming macOS updates by testing how your application behaves under stricter permission grant workflows.



