Back to feed

Apple announced clearer approval steps for the Mac full disk access permission, arguing that increasingly capable AI agents make broad access riskier. The debate began when Meta's Muse agent was accused of reading private messages.

Why Apple Is Locking Down Mac Full Disk Access in the Age of AI Agents

Imported to Nodesdaily: (UTC+03:00)
Watch on YouTube — techcrunch:3173313
Reading options

Device speech is unavailable in this browser.

Concept lens

Choose a technical term in this view to read its general definition, teaching example and use in the article.

No terms from our glossary were found in this view. The glossary does not cover every term yet.

Imagine a Mac app that knows the contents of private messages its user swears were never shared with it; that sounds like a spy movie, yet exactly such a claim dominated the tech debate last week. Inc. columnist Jason Aten wrote that Meta's AI agent Muse knew about his personal chats even though, he says, he never granted access. An AI agent , in short, is software that reads files, clicks buttons and takes actions on its user's behalf. Meta rejected the claim, but the argument had already grown: how much power do we really hand to programs that act for us on the desktop?

Days later Apple announced fresh checks around the macOS setting called full disk access . Once switched on, it opens a wide gate designed so backup tools work properly, reaching emails, messages and browsing history. According to the company's developer note, some makers use this permission in ways users do not fully grasp. Apple says that from now on, anyone who genuinely wants this extraordinary access will grant it only through very explicit action. The heart of the move is explicit user consent : everybody should plainly see what is being allowed. Reporting on businessinsider.com confirms the same picture, noting Apple plans tougher Mac privacy checks as AI agents grow more capable.

How a backup permission became the agents' master key

The short history of Mac permissions shows why the tightening surprises few. In 2018, with Mojave, Apple shipped its transparency, consent and control architecture, known as TCC, which logs exactly which app may touch mail, messages or photos. Full disk access was the exception to that careful design: a pass that skips the checks so backup tools can reach every file. Today's desktop agents lean precisely on that exception, entering the whole house with a single key. That historical frame is told in detail by the Mac privacy history on eclecticlight.co, which traces two decades of permission design rather than a single scare.

In the Muse case the two narratives clash head-on. Aten says the messaging connector stayed off, while Meta executive David Singleton argues the integration is opt-in: reading messages needs both system-level full disk access and the in-app connector switched on. The company thus implies the user turned the key if the door stood open. Security specialists answer with the technical fact: any program holding full disk access can already read every file that needs no root rights. That rebuttal is carried by analysis on arstechnica.com, which quotes macOS security specialist Patrick Wardle saying chats and browser data become readable under this permission.

Nor is this the first Mac AI security test. The ChatGPT Mac app once drew fire for storing chats as plain text, and researchers warned hostile software could reach those files. So the flaw is not one company's; it is architectural: agents demand broad access to do their jobs, and broad access magnifies every bug. That older hole was documented in depth by the security file on wired.com, which describes work showing hostile code could reach sensitive data.

Broad power, big danger: why agents are a special threat

Prompt injection , where an agent mistakes foreign text on screen for a user order and obeys it, is the sneakiest form of this danger. In a chat window a hostile sentence yields at most a wrong answer, yet an agent that reads files and presses buttons performs real operations when fooled: moving files, sending messages, running commands. The capability called computer use hands the model screenshots plus mouse and keyboard, multiplying the attack surface. That risk map is drawn with concrete cases by the security review on mindstudio.ai, which finds newer models somewhat more resistant while warning no production system should trust model judgment alone.

Yet there is another side: strict checks can hurt honest developers and power users. Noted Mac commentator John Gruber writes that several tools he relies on daily need full disk access and would be crippled by repeated approval prompts. For him the problem is not the permission itself but vague approval screens that never explain what an app wants. That critical view is voiced plainly in the assessment on daringfireball.net, which worries that shielding novices may break expert workflows. If Apple's fix keeps that balance, it moves toward the least privilege rule: give each program only the access its job needs.

Visualization: nodesdaily AI

AI commentary

"I think Apple is pushing the right door but has yet to describe the lock; opening the whole disk with one switch feels outdated. I would not wait for the new screen and would review my permission list today."

AI assessment

The strongest counterargument comes from Meta: the company says reading messages needs two separate explicit permissions, so no closed door was forced. If that defense holds, the Aten case may be an interface misunderstanding rather than a rule breach; the user may have tapped both switches unknowingly. Yet even that strengthens Apple's thesis instead of refuting it: if people barely grasp what they tap, a design that opens the whole disk with one switch is already broken.

Apple's announcement still leaves wide gaps: when the new checks arrive, what they look like, and whether past grants get restricted retroactively all stay unclear. The company promises no narrower model that grants file-by-file access; what is promised is a stronger consent screen. If the screen grows scarier while the scope stays broad, the root of the danger remains; the user merely clicks a more frightening warning.

The takeaway for readers is concrete: open the full disk access list in Mac System Settings today, revoke permissions from unknown or unused apps, and never hand AI agents the widest powers at first setup. Keeping the account that holds sensitive chats and work files away from experimental agents on the same machine is a simple yet effective shield. Permission is not a deed of trust but a lease; its term and scope must stay defined.

Sources

7 links; no other published story cites them. Stories sharing a link do not confirm each other; a source's origin is not inferred from how often it is cited.

artificial intelligence · apple · macos · privacy · security

Follow the topic

Before this story

A short reading order from earlier stories linked to this event by an editor.

Evidence and sources

Review permitted source passages, versions and origins.

KAYNAKLARLA OKU

Bu haberi açalım.

Hesap kontrol ediliyor…