Apple changes full-disk access permissions to curb abuse from AI agents
Apple is modifying its macOS privacy settings to prevent third-party app developers from misusing full-disk access to view message histories. This change comes after concerns were raised about AI agents potentially accessing sensitive user data. A security expert, Patrick Wardle, questioned Meta's denial that its Muse app could not read messages despite having full-disk access, stating that technically, full-disk access allows reading of any non-root file, including browsing history, cookies, and chats.
This report details Apple's first change to macOS full-disk access permissions specifically to curb AI agent abuse, unlike previous privacy adjustments.
时间与来源
时间显示为 UTC
显示时区:UTC
本地时区尚不可用,暂时显示 UTC。
发布当时偏移:UTC+02026年10月2日 23:03 UTC
收录当时偏移:UTC+02026年10月3日 00:00 UTC
- 发布
- 2026年10月2日 23:03
- 收录
- 2026年10月3日 00:00
- 来源类型
- 媒体报道
- 档位
- 专业媒体
- 信源状态
- 正常
档位是按信源手工设定的编辑判断,不是逐条打分。
讨论趋势
百分比基于采集到的讨论信号,不代表新增评论数或独立参与人数。曲线仅用于同一话题在不同时段的比较。
Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories.
Friday’s announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.
He said/she said
Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.
“The Messages integration in the Muse Mac app is opt in,” Singleton said. “Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”
Singleton’s implication was clear. Muse could have read Aten’s Messages communications only if he had enabled both settings, and if so, the columnist had only himself—and certainly not Meta—to blame.
Earlier this week, I spoke to macOS security expert Patrick Wardle, who questioned Singleton’s denial. His reasoning: “From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc.” I asked Meta how Muse couldn’t read messages when the app had full disk access, while every other app with that privilege could. Meta PR’s only response was to requote Singleton saying: “The Messages integration in the Muse Mac App is opt-in. Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”