AI Agent Surge Makes Apple Revise Mac App Data Access Rules

Apple plans more explicit consent for Full Disk Access, the Mac permission that lets apps reach private files and messages.

TL;DR
  • App Consent: Apple plans more explicit consent before apps receive Full Disk Access, a macOS permission that opens private files and communications.
  • Messages Dispute: Meta denies that its Muse AI assistant read a columnist’s messages without permission; the columnist questions whether users understand the access.
  • Malware Risk: A separate ChatGPT Mac flaw could expose app data through malware already on the computer; OpenAI has reported a fix.
  • Grant Process: Apple’s promise preserves deliberate broad grants; its notice leaves the new confirmation process and treatment of existing permissions unspecified.

Apple plans to require more explicit user action before Mac apps receive Full Disk Access, the permission that lets them reach private files, mail and messages. In its October 2 developer notice, Apple warns that increasingly autonomous AI agents raise the stakes of granting that access, including for people whose conversations are stored on someone else’s Mac.

Apple’s notice says people who want to grant it will still be able to do so, but gives no release date or description of the additional controls.

How One Permission Opens Private Data

macOS ordinarily asks for consent when apps access protected resources such as Documents, Desktop and Downloads folders, iCloud Drive and network volumes. Apps needing access to the full storage device already have to be explicitly added in privacy settings.

Full Disk Access reaches beyond a single folder. Apple says the permission largely bypasses its private-data controls so backup software can work properly. That reach can also expose mail, messages and browsing history to other apps that receive the grant. With a communication app, the Mac user’s decision can consequently expose information belonging to the people they talk to.

Desktop agents use access to do work rather than merely answer questions in a chat window. In July, Google’s Gemini Spark Mac beta illustrated that utility with file sorting and budget-spreadsheet tasks on files users permitted it to use.

Apple’s stated concern is that some developers use the broad permission without users fully understanding the exposure. Its planned requirement for “very explicit user action” addresses that understanding as agents become more capable of acting independently.

The Muse Dispute Turns on What Users Authorized

The announcement followed a disputed account from Inc. technology columnist Jason Aten about Meta’s Muse AI agent that can work in the background on connected data. Aten reported that it unexpectedly referenced a private Apple Messages conversation with a co-worker. He said Full Disk Access was disabled.

Meta disputes the claim that Muse read messages without permission. Communications vice president Andy Stone said users need to enable both Full Disk Access and Muse’s Messages connector. Meta executive David Singleton described additional confirmation in macOS settings and an app restart before message access works.

When Aten asked how Muse knew about his conversations, the assistant attributed its knowledge to notification banners. Singleton said that explanation was wrong, according to the reported exchange.

Aten’s objection also concerns informed consent. In a follow-up shared by Daring Fireball, he argued that a consumer app should explain that it can read text messages without expecting its audience to understand macOS permission architecture.

Full Disk Access defines what protected data macOS allows an app to reach; Meta describes the Messages connector as an additional control over what Muse reads. Security researcher Patrick Wardle of the Objective-See Foundation questioned Meta’s two-permission requirement, pointing to the OS grant’s broad file-reading capability.

A Separate Flaw Shows How App Access Can Amplify Malware

Objective-See Foundation researchers found a flaw in how ChatGPT’s Mac app checked software components it treated as trusted. Malware already installed on a computer could exploit it to act through the app’s trusted process, WIRED reported on October 2.

Wardle demonstrated the possibility of reaching app-held information and connected resources. WIRED reported that OpenAI acknowledged and fixed the flaw in its September 25 changelog.

Preserving Useful Access While Making Consent Clearer

Meta’s Muse security design describes controls intended to constrain agent actions. A separate permission system applies user-set rules that allow, deny or request approval for connector operations. Where a connected service supports it, read and write access can be separated, giving users a way to permit information retrieval while restricting changes.

Daring Fireball argues for preserving powerful Mac workflows, noting that several apps its author uses depend on Full Disk Access. Its author worries that repeated authorization could disrupt those workflows.

Markus Kasanmascheff
Markus Kasanmascheff
Markus has been covering the tech industry for more than 15 years. He is holding a Master´s degree in International Economics and is the founder and managing editor of Winbuzzer.com.
Subscribe
Notify of
guest
0 Comments
Newest
Oldest Most Voted