Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Apple will tighten macOS Full Disk Access after AI agents raised risks of apps reading private files and messages.
Apple said it will add controls so macOS Full Disk Access is granted only after very explicit user action. The company warned that some developers use the setting in ways that can expose files, mail, messages, and browsing history without users fully understanding the risk. The announcement follows a disputed report that Meta’s Muse app read a journalist’s private messages and earlier reporting that a ChatGPT Mac app flaw could have exposed sensitive data. Apple said the risk will grow as desktop AI agents become more capable and autonomous.
- Apple will require very explicit consent before granting Full Disk Access.
- That permission can expose files, mail, messages, and browsing history.
- The move follows a disputed claim that Meta Muse read private messages.
- Apple says more autonomous AI agents substantially raise this access risk.
- Earlier reporting said a ChatGPT Mac flaw could expose sensitive data.
Full article437 words · extracted from techcrunch.com · click to collapse
Days after a journalist claimed that Meta’s Muse app on Mac read their private messages — a claim that Meta disputed — Apple announced that it’s introducing additional controls around a setting called “Full Disk Access” on macOS. The feature was designed to allow backups to function properly, but AI agents have now increased “the risks associated with this level of access,” Apple said.
Apple’s statement comes shortly after Inc. columnist Jason Aten reported that Muse knew the content of his private messages — even though he claimed to have not given the AI agent permission. The report raised questions about the level of security and trust users have in desktop-based AI, which can control things on their systems and read their files and messages.
The decision to limit the Mac feature also comes after a Wired report cited that a flaw in ChatGPT’s Mac app could have allowed hackers to access sensitive data.
AI agents that run on the desktop allow users to provide their respective apps with greater access to the files, messages, and other personal content on their computers by adjusting macOS settings.
In Muse’s case, the AI optionally allows users to enable Full Disk Access. This setting, Apple explains, gives an app permission to access files, mail, messages, and even browsing history.
“Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems…without users’ full knowledge and understanding,” Apple said in a new blog post aimed at developers.
The company says that, going forward, it will introduce new controls aimed at ensuring that users who “genuinely wish to grant an app this extraordinary level of access” can do so only with “very explicit user action.”
“Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” Apple wrote.
Apple did not respond to TechCrunch’s inquiry about the feature change.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Prior to her work as a reporter, Sarah worked in I.T. across a number of industries, including banking, retail and software.
You can contact or verify outreach from Sarah by emailing sarahp@techcrunch.com or via encrypted message at sarahperez.01 on Signal.