Skip to main content
The Wire
CyberNews by Zentrya One
Vulnerabilities

Apple Tightens macOS Full Disk Access as AI Agents Raise Privacy Risks

Apple plans stronger macOS Full Disk Access controls as increasingly autonomous AI agents raise concerns about access to files, emails, messages, browsing history and other sensitive user data.

Apple is preparing stronger controls around Full Disk Access (FDA) in macOS, warning that increasingly capable AI agents could expose sensitive information when applications are granted extensive access to a Mac.

Full Disk Access can allow an application to reach protected information including files, emails, messages, browsing history and Time Machine backups. Apple says some developers are using the permission in ways that may expose significantly more information than users realize.

Why Full Disk Access Is Powerful

Full Disk Access exists because certain applications—particularly backup and security software—legitimately require broad access to system data.

However, granting FDA effectively allows an application to bypass several macOS privacy restrictions.

For an AI agent capable of interacting with applications and performing actions autonomously, the potential exposure becomes much greater:

User Grants FDA → AI Agent Accesses Protected Data → Agent Processes Sensitive Information → Compromise or Abuse Could Expose That Data

Apple warns that these risks will increase as AI agents become more capable and autonomous.

Apple Plans More Explicit User Approval

Apple says future macOS changes will introduce additional controls so applications can receive Full Disk Access only following very explicit user action.

The goal is to ensure users understand the amount of information an application could access before granting the permission.

Apple has not yet announced exactly how the new controls will work or when they will be released.

AI Agents Put FDA Under the Spotlight

The announcement follows growing security concerns surrounding AI agents that receive broad operating-system permissions.

One recent example involved Meta's Muse AI agent. Reports showed that the application could access private iMessages after Full Disk Access was granted.

Meta clarified that its Messages integration is opt-in and requires two conditions: the Muse application must have macOS Full Disk Access and the Messages connector inside Muse must also be enabled.

Security researcher Patrick Wardle also disclosed a now-patched vulnerability affecting Muse's Mac application that could allow an unprivileged local process to interfere with the agent's dictation traffic, potentially capturing prompts and abusing permissions already granted to the AI application.

Why AI Agents Change the Risk

Traditional applications typically use elevated permissions for a defined set of functions.

AI agents can potentially perform a much wider range of actions, including:

  • Reading and writing files
  • Accessing messages and emails
  • Using microphones and cameras
  • Creating calendar events
  • Interacting with other applications
  • Processing sensitive personal information
  • Performing actions autonomously

This creates a potential privilege amplification problem.

If an attacker compromises or manipulates an AI agent that already has powerful macOS permissions, the attacker may be able to abuse the agent's trusted access rather than directly bypassing macOS security controls.

What Mac Users Should Do

Mac users should regularly review applications with Full Disk Access under:

System Settings → Privacy & Security → Full Disk Access

FDA should only be granted to applications that genuinely require it.

Users should be particularly cautious when AI assistants or agentic applications request broad permissions and should review what data sources, connectors and integrations are enabled.

Apple's existing security guidance emphasizes that users should maintain transparency and control over applications accessing their information.

Security Takeaway

Apple's decision reflects a broader security challenge created by increasingly autonomous AI agents.

The concern is no longer simply:

“Can this application access my files?”

It increasingly becomes:

“What can an autonomous agent do with everything this application is allowed to access?”

Apple's planned Full Disk Access changes aim to make granting such powerful privileges a more deliberate decision, reducing the likelihood that users unknowingly provide AI applications with extensive access to sensitive information.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.