Apple Tightens macOS Full Disk Access as AI Agents Become More Powerful
Apple will tighten macOS Full Disk Access so users deliberately approve broad access as AI agents grow more capable.
Apple said it will add stronger controls to macOS Full Disk Access because the permission can expose files across a Mac plus Mail, Messages, Safari, Home, Time Machine backups, and some system settings. The company warned that some developers request this access in ways users may not understand, and that AI agents able to read multiple sources and act independently increase the risk. Apple has not shared the design, release date, or supported macOS versions, and the change is not described as removing access for legitimate backup, security, or recovery tools. Users are advised to review Privacy & Security settings and remove grants that are unused or unnecessary.
- Full Disk Access can expose Mail, Messages, Safari, backups, and settings.
- Apple wants deliberate approval rather than a simple permission toggle.
- No design, release date, or supported macOS versions were published.
- Users should revoke Full Disk Access for unused or unnecessary apps.
Full article567 words · extracted from cybersecuritynews.com · click to collapse
Apple plans to add stronger controls to Full Disk Access in macOS, warning that the powerful permission can expose a user’s most private data as AI agents become more capable. The company said the change will require users to take a far more deliberate action before granting an app this broad level of access.
Full Disk Access was built to help trusted Mac tools, mainly backup software, work around normal privacy limits when needed. However, the permission can let an app reach files across the Mac, along with data held by Mail, Messages, Safari, Home, Time Machine backups, and certain system settings.
Apple’s current guidance already treats the setting as a high-risk permission, requiring users to manually add an app through the Privacy & Security section of macOS settings.
Apple Tightens macOS Full Disk Access
Apple said some developers are using Full Disk Access in ways that may leave users unaware of how much information an app can see. The concern is not limited to documents stored on the device.
A granted app may be able to access email, private chats, browsing history, and other personal records that are normally protected by macOS controls. For communication tools, the privacy impact can also extend to other people involved in those conversations.
The growing use of AI agents makes this issue more serious. Unlike a normal app that performs one clear task, an AI agent may read information from several sources, process it, and take further actions based on what it finds.
Broad disk access could therefore give an agent visibility into a large amount of personal or business data. Apple said the risks will grow substantially as these tools become more capable and act with greater independence.
Apple has not yet shared the exact design, release date, or supported macOS versions for the additional controls. Still, its wording suggests the company wants to move beyond a simple permission toggle and make users clearly understand the scope of access before enabling it.
The change does not appear to remove Full Disk Access from legitimate backup, security, or recovery tools. Instead, it aims to make sure people consciously approve an exceptional permission rather than enabling it while rushing through an app setup process.
For Mac users, the immediate step is to review the existing list of apps with Full Disk Access. Open System Settings, select Privacy & Security, and then choose Full Disk Access.
Remove access for tools that are no longer used or that do not have a clear need to read data from across the system. This is particularly important for desktop AI assistants, browser extensions, system cleaners, and communication apps.
The move also follows wider concern about weaknesses around macOS Transparency, Consent, and Control protections. Cyber Security News recently reported on a macOS TCC bypass vulnerability and on the growing risks of AI agents carrying out ransomware activity.
Apple’s planned update shows that strong permission design is becoming a key security control as AI software gains deeper access to user devices.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.