Apple Tightens macOS Full Disk Access Over AI Agent Risks — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Apple announced plans to tighten macOS Full Disk Access controls, warning that some developers use the setting to expose users' files, mail, messages, and browsing history without their full knowledge.
- Apple said it will update Full Disk Access — introduced in macOS Mojave (10.14) — so the permission is granted only with explicit user action, though no rollout timeline was provided.
- The move appears to respond to a report that Meta's Muse personal AI agent read a journalist's private iMessages after Full Disk Access was granted; Meta CTO David Singleton said the Messages integration is opt-in and requires both FDA and an in-app Messages connector.
- Patrick Wardle demonstrated a proof-of-concept exploit dubbed 'not-a-mused' for a zero-day in Muse's Mac app that let any unprivileged local process capture the auth token, redirect dictation traffic, and inject malicious prompts.
- Wardle also reported CVE-2026-100754, a now-acknowledged vulnerability in OpenAI's ChatGPT Mac app that could have been abused to hijack the assistant and access stored chat logs and other data.
Why it matters: Apple's move directly targets the privileged position of agentic AI tools like Meta's Muse, which can read messages, files, microphone, and camera. With Wardle's zero-day PoC in Muse and a separate ChatGPT Mac flaw already disclosed, Apple is shifting from implicit OS-level trust to mandatory, granular user consent for any app seeking FDA.
Ask SkimNews




