Skip to content
ACarstechnica.com·

Apple changes full-disk access permissions to curb abuse from AI agents

AI summary

Apple is modifying its macOS privacy settings to prevent third-party app developers from misusing full-disk access to view message histories. This change comes after concerns were raised about AI agents potentially accessing sensitive user data. A security expert, Patrick Wardle, questioned Meta's denial that its Muse app could not read messages despite having full-disk access, stating that technically, full-disk access allows reading of any non-root file, including browsing history, cookies, and chats.

Why this one

This report details Apple's first change to macOS full-disk access permissions specifically to curb AI agent abuse, unlike previous privacy adjustments.

Time & source

Times shown in UTC

Display time zone: UTC

Local time zone unavailable; showing UTC.

PublishedOffset at this time: UTC+0Oct 2, 2026, 23:03 UTC

IngestedOffset at this time: UTC+0Oct 3, 2026, 00:00 UTC

Published
Oct 2, 2026, 23:03
Ingested
Oct 3, 2026, 00:00
Source type
Media
Tier
Press
Source status
Healthy

Tier is a per-source editorial setting, not a per-item score.

Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories.

Friday’s announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.

He said/she said

Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.

“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”

Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.

Earlier this week, I spoke to macOS security expert Patrick Wardle, who questioned Singleton’s denial. His reasoning: “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc.” I asked Meta how Muse couldn’t read messages when the app had full disk access, while every other app with that privilege could. Meta PR’s only response was to requote Singleton saying: “The Messages integration in the Muse Mac App is opt-in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”