Apple changes full-disk access permissions to curb abuse from AI agents
Apple is tightening macOS full-disk access after Meta’s Muse agent was reported reading Apple Messages.
Apple said it is changing macOS privacy settings so third-party developers cannot misuse them to read message histories. The announcement follows columnist Jason Aten’s report that Meta’s Muse AI agent referenced an Apple Messages thread he said he never authorized it to read. Meta CTO David Singleton said Messages access is opt-in and requires both macOS Full Disk Access and a Muse Messages connector. macOS researcher Patrick Wardle countered that Full Disk Access already lets an app read non-root files, including chats, cookies, and browsing history.
- Apple is changing macOS privacy settings to limit message-history access
- Meta’s Muse agent allegedly referenced a private Apple Messages thread
- Meta says access requires Full Disk Access and an opt-in Messages connector
- Researcher Patrick Wardle says FDA can already read chats, cookies, and history
Full article341 words · extracted from arstechnica.com · click to collapse
Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories.
Friday’s announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill aw or other power tool. While potentially useful, they can do real damage if not used carefully.
He said/she said
Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.
“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”
Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.
Earlier this week, I spoke to macOS security expert Patrick Wardle, who questioned Singleton’s denial. His reasoning: “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc.” I asked Meta how Muse couldn’t read messages when the app had full disk access, while every other app with that privilege could. Meta PR’s only response was to requote Singleton saying: “The Messages integration in the Muse Mac App is opt-in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/