Apple Tightens macOS Full Disk Access Controls Over AI Agent Security Risks

Apple has announced plans to tighten controls around Full Disk Access (FDA), a powerful macOS permission, citing growing security and privacy risks from artificial intelligence (AI) agents.

Why Apple Is Making the Change

In a recent post, Apple said some developers are using Full Disk Access in ways that put users at risk, exposing files, mail, messages, and browsing history without users fully understanding what they have allowed. The company added that for communication apps, this also threatens the privacy of the people users talk to.

Apple warned that as AI agents grow more capable and autonomous, the risks tied to this level of access will increase significantly. The company said it wants users to clearly understand these risks before granting such permissions.

What Is Full Disk Access

Full Disk Access was introduced in macOS Mojave (version 10.14) and can be found under Privacy & Security in the Settings app. It lets users decide which apps can access their entire system, including data from Mail, Messages, Safari, and Time Machine backups.

Once enabled, the permission allows an app to bypass certain security restrictions and read or modify system files that are normally off limits. Security tools and backup software often rely on it to work properly.

What Changes Are Coming

Apple said Full Disk Access largely bypasses the protections built to safeguard private data. Future updates will make sure this access is granted only through an explicit user action. Apple has not shared a timeline for when the new controls will roll out.

The Meta Muse Connection

While Apple did not name any company, the move appears linked to a recent report showing that Meta's Muse agentic tool accessed a journalist's private iMessages after being granted Full Disk Access. Muse is marketed as a personal AI agent, built along the lines of OpenClaw, and runs on a dedicated Linux virtual machine in Meta's cloud.

Meta CTO David Singleton clarified that Muse's Messages integration is opt in. According to Meta, Muse can read Messages content only when two conditions are met: macOS Full Disk Access is granted, and the Messages connector is enabled inside Muse.

Zero-Day in Muse Mac App

The announcement also follows research by security expert Patrick Wardle, who recently demonstrated a proof-of-concept exploit for a zero-day in the Muse Mac app, dubbed not-a-mused. The flaw, now patched, allowed any app or terminal command to grab the token that authenticates users to their Muse account.

Wardle explained that the bug could let an unprivileged local process redirect Muse's dictation traffic and abuse the trust and access granted to the app. He noted that because Muse may have far broader access than typical local malware, it becomes an especially valuable target.

The attack relied on an undocumented setting called "endo_voyager_dictation_endpoint." Without any special privileges, a local attacker could use it to capture dictated audio and prompts, inject malicious prompts, and misuse Muse's permissions for other harmful actions.

ChatGPT Mac App Flaw

Wardle was also credited with reporting CVE-2026-100754, a vulnerability in OpenAI's ChatGPT app for Mac. The flaw could have allowed an attacker to take over the assistant and gain unauthorized access to chat logs and other stored data.

Key Takeaway

AI agents often hold privileged positions on a device, collect large amounts of data, and can write files, use the mic and camera, create calendar events, send emails, and track location. This makes them attractive targets for attackers. Apple's move to restrict Full Disk Access reflects a broader shift toward limiting how much power AI tools get by default. Until the new controls arrive, users should review which apps have Full Disk Access and remove it from any that do not truly need it.