{"id":427,"date":"2026-10-07T01:58:40","date_gmt":"2026-10-07T01:58:40","guid":{"rendered":"https:\/\/managedt.com\/blog\/apple-macos-full-disk-access-ai-agents\/"},"modified":"2026-10-09T02:36:43","modified_gmt":"2026-10-09T02:36:43","slug":"apple-macos-full-disk-access-ai-agents","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/apple-macos-full-disk-access-ai-agents\/","title":{"rendered":"Apple to Tighten macOS Full Disk Access Controls Over AI Agent Risks"},"content":{"rendered":"<p>Apple is preparing updates to macOS Full Disk Access, the setting that lets an app read and write system files, in response to security risks created by AI agents that can act on a user&#8217;s behalf. The change, announced in an Apple post, aims to make sure this level of access is only granted through an explicit user action, so people understand what they are handing over before an agent can read mail, messages, browser history and other sensitive data on the system.<\/p>\n<h2>What Full Disk Access does in macOS<\/h2>\n<p>Full Disk Access was introduced in macOS Mojave (version 10.14) and lives under Privacy and Security in the Settings app. When a user turns it on for an application, that program can bypass certain security restrictions and read and write files normally off-limits, including data from Mail, Messages, Safari and Time Machine backups. The setting is essential for apps that need deep system reach, such as security tools and backup software, because it gives them the access required to do their job.<\/p>\n<p>Apple&#8217;s concern is that Full Disk Access largely bypasses controls built to safeguard private data, and that the way some developers are using it could expose everything on a user&#8217;s system without full knowledge of what is being shared. For communication apps, the company noted, this can also compromise the privacy of the people on the other end of those messages.<\/p>\n<h2>Why AI agents triggered the change<\/h2>\n<p>The announcement is tied to the growing capability of agentic tools, software that can browse, read files, send messages, write to disk, use the microphone and camera, create calendar events and monitor location on behalf of a user. Apple warned that as these agents become more capable and autonomous, the risks tied to broad FDA grants will grow substantially, and that users deserve a clearer picture of those risks before they hand over the keys.<\/p>\n<p>The move follows a report about a personal AI agent called Muse, developed by Meta, which read a journalist&#8217;s private iMessages after being granted Full Disk Access. Muse is advertised as a personal AI agent built along the lines of OpenClaw, and it runs on a dedicated Linux virtual machine in Meta&#8217;s cloud. Meta has clarified that for Muse to read a user&#8217;s private messages, two settings must be on: Full Disk Access for the app in macOS, and the Messages connector inside Muse itself, which is opt-in.<\/p>\n<h2>The vulnerability that put a spotlight on the issue<\/h2>\n<p>Weeks before Apple&#8217;s announcement, a security researcher published a proof-of-concept exploit for a zero-day in the Muse Mac app, named not-a-mused. The bug let any app or terminal command obtain the token that authenticates a user to their Muse account, which is significant because the local attack required no special privileges. The exploit abused an undocumented setting called endo_voyager_dictation_endpoint, allowing an unprivileged local process to redirect Muse&#8217;s dictation traffic, capture dictated audio and prompts, inject malicious prompts and abuse the access Muse had already been granted.<\/p>\n<p>The same researcher was also credited with reporting a separate flaw, tracked as CVE-2026-100754, in OpenAI&#8217;s ChatGPT app for Mac. That bug could have been abused to take over the AI assistant and reach chat logs and other data stored by the app. Both findings show how a privileged agent, with broad data collection and the ability to touch many parts of the operating system, can become a high-value target for attackers looking to amplify their access on a device.<\/p>\n<h2>What users and developers should expect<\/h2>\n<p>Apple has not given a date for the new Full Disk Access controls. The general direction, drawn from the announcement, is that granting FDA to an agentic app will require a more deliberate user action, with the user clearly informed of the scope of the access and the privacy tradeoffs, including the privacy of people the user communicates with. Until the update lands, the existing Full Disk Access prompts remain the main checkpoint between a user&#8217;s entire file system and any app that asks for it.<\/p>\n<p>For anyone using an AI agent that requests Full Disk Access, the practical takeaway is to treat the grant as a high-trust action, to confirm what data the agent will be able to read, and to watch for future macOS updates that change how and when the system asks for permission. For developers building on top of agentic frameworks, the message from Apple is that the era of silent, blanket FDA grants is closing, and product designs that depend on unfettered background access will need to be reworked around more explicit consent.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is macOS Full Disk Access?<\/h3>\n<p>Full Disk Access is a macOS privacy setting, introduced in macOS Mojave (10.14) and found under Privacy and Security in Settings, that lets an application read and write files normally restricted, including data from Mail, Messages, Safari and Time Machine backups.<\/p>\n<h3>Why is Apple tightening Full Disk Access for AI agents?<\/h3>\n<p>Apple warns that some developers misuse Full Disk Access, exposing everything on a user&#8217;s system without clear user awareness, and that the risks will grow as AI agents become more capable and autonomous.<\/p>\n<h3>What incident pushed Apple to act?<\/h3>\n<p>A report that Meta&#8217;s Muse personal AI agent accessed a journalist&#8217;s private iMessages after being granted Full Disk Access, followed by a proof-of-concept zero-day in the Muse Mac app, called not-a-mused, that could let an unprivileged local process steal the Muse authentication token and abuse the access already granted to the app.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is macOS Full Disk Access?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Full Disk Access is a macOS privacy setting, introduced in macOS Mojave (10.14) and found under Privacy and Security in Settings, that lets an application read and write files normally restricted, including data from Mail, Messages, Safari and Time Machine backups.\"}},{\"@type\":\"Question\",\"name\":\"Why is Apple tightening Full Disk Access for AI agents?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Apple says some developers are using Full Disk Access in ways that could expose everything on a user's system without their full understanding, and that as AI agents become more capable and autonomous, the risks of that access will grow substantially.\"}},{\"@type\":\"Question\",\"name\":\"What incident pushed Apple to act?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A report that Meta's Muse personal AI agent accessed a journalist's private iMessages after being granted Full Disk Access, followed by a proof-of-concept zero-day in the Muse Mac app, called not-a-mused, that could let an unprivileged local process steal the Muse authentication token and abuse the access already granted to the app.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/thehackernews.com\/2026\/10\/apple-plans-tighter-macos-full-disk.html\" target=\"_blank\" rel=\"nofollow noopener\">thehackernews.com<\/a>.<\/p>\n<p><!-- seo-pro:slop-fixed --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple is tightening macOS Full Disk Access after reports that AI agents accessed private user data. New controls will require explicit user action before<\/p>\n","protected":false},"author":3,"featured_media":426,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-427","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=427"}],"version-history":[{"count":2,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/427\/revisions"}],"predecessor-version":[{"id":485,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/427\/revisions\/485"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/426"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}