Apple announced plans to tighten macOS Full Disk Access controls as increasingly capable and autonomous AI agents raise privacy risks. The permission gives applications broad access to sensitive information, including files, mail, messages, and browsing history. Apple warned that some developers use this access without users fully understanding the exposure and said future controls will require very explicit user action to authorize it. The company provided no implementation timeline and did not identify a specific breach or vulnerability in its announcement.
The announcement followed columnist Jason Aten’s allegation that Meta’s Muse app knew the contents of his private messages without permission, a claim Meta disputed. TechCrunch also cited a separate Wired report about a flaw in ChatGPT’s Mac app that could have allowed hackers to access sensitive data. These concerns underscore the need for organizations to review which desktop applications and AI agents hold Full Disk Access, limit grants to justified business requirements, and ensure users understand the scope of the permission while awaiting Apple’s changes.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Apple announced additional Full Disk Access controls that will require very explicit user action, warning that increasingly autonomous AI agents heighten risks to private data. Apple did not disclose an implementation timeline.
Meta disputed Jason Aten’s claim that Muse had read his private messages without permission.
Inc. columnist Jason Aten reported that Meta’s Muse app knew the contents of his private messages, claiming he had not granted it permission to access them.
Wired reported a flaw in ChatGPT’s Mac app that could have allowed hackers to access sensitive data. The reference did not identify confirmed exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.