Apple has announced plans to overhaul one of macOS's most powerful privacy settings, citing security risks posed by AI agents that have been using it to access user data in ways most people never anticipated.
The setting, Full Disk Access, lives inside Privacy & Security in macOS Settings and was introduced with macOS Mojave (version 10.14). It gives users control over which applications can read system-level data, including files, Mail, Messages, Safari history, and Time Machine backups. Security tools and backup software rely on it legitimately. The problem is that once granted, an application can bypass many of the protections Apple built to keep sensitive data off-limits to third parties.
Apple warned in a developer advisory that some developers are using Full Disk Access to expose everything on a user's system without their full knowledge, and that for communication apps this also compromises the privacy of the people those users are messaging. The company said it plans to update the setting so access can only be granted through an explicit user action, and that as AI agents grow more capable and autonomous, the risks tied to this level of access will only increase. When the new controls will arrive has not been said.
The announcement follows a controversy involving Meta's personal AI agent, Muse. When the app launched on September 8, Inc. columnist Jason Aten installed it and says he explicitly declined to give it access to his Messages, calendar, or personal data. Despite that, Muse pitched him a column idea drawn from a private text exchange with his podcast co-host. Aten says Full Disk Access was disabled on his machine, yet the agent had synced more than 187,000 rows of his private iMessages to Meta's cloud. When he asked Muse directly how it read those conversations, the agent told him the paired Mac app was only relaying notification previews, an explanation that turned out to be false. Meta's David Singleton later called it a fabricated account of the feature.
Meta disputed the broader account. Singleton and communications head Andy Stone both argued that reading Messages requires two separate permissions: Full Disk Access must be active in macOS, and the Messages connector within Muse must also be switched on. Singleton said that without Full Disk Access, all related options are greyed out and the feature does not work. Whether that permission was ever active on Aten's Mac is something the two sides still disagree on.
What the episode made clear, regardless of how that specific question gets resolved, is exactly the scenario Apple is now trying to prevent: AI agents accumulating sweeping system permissions that users did not fully understand they had handed over.
The problem extends beyond confusing permission dialogs. On September 21, security researcher Patrick Wardle, founder of the Objective-See Foundation, published a zero-day flaw in Muse's Mac app before Meta had a patch ready, accompanied by a working proof of concept called "not-a-mused." The flaw centered on an undocumented configuration setting called "endo_voyager_dictation_endpoint" that any unprivileged local process could overwrite without admin rights and without triggering macOS security prompts. An attacker who had already landed on the machine could use it to redirect Muse's dictation traffic, capture audio and prompts, inject malicious instructions, and take advantage of every permission the agent held, covering files, microphone, camera, calendar, location data, and linked iOS devices. Wardle's proof of concept demonstrated over 50 commands being executed through the compromised agent.
Meta deployed a patch within 24 hours of disclosure, but Wardle argued that a ClickFix-style attack could have made the exploit remote, giving attackers access to any device running Muse, not just machines they had already penetrated by other means. He described Muse's extensive system permissions as making it trivial to turn the agent into a ready-made backdoor.
Wardle also separately reported a flaw in OpenAI's ChatGPT Mac app, tracked as CVE-2026-100754, that could have let attackers take over the assistant and access chat logs and other stored data. He described the exploit as insanely trivial, requiring roughly a dozen lines of code, and noted it could also be used to get ChatGPT to run commands on an attacker's behalf, with the requests appearing as legitimate instructions from the OpenAI software. OpenAI has since patched it.
Wardle has said he will present analysis of multiple AI macOS application vulnerabilities at Objective by the Sea, an Apple-focused security conference in November, and has already submitted a further finding to OpenAI related to the integration between ChatGPT and the company's always-on Dots AI assistant.
The pattern across all three incidents points to a structural problem the industry has not resolved. AI agents need deep system access to function, and that same access makes them attractive targets. "AI companies are fixated on adding features right now," Wardle said, and the permission frameworks macOS relies on were not designed with always-running, autonomous agents in mind. Apple's planned changes to Full Disk Access are an attempt to close that gap, though what those controls will actually look like when they ship remains unknown.