Apple changes full-disk access permissions to curb abuse from AI agents
Apple announced changes to macOS privacy controls aimed at preventing third-party apps from misusing system permissions to read message histories. The move follows a report that Meta’s new AI agent Muse referenced a private Apple Messages thread, prompting debate over whether system-level Full Disk Access permissions can allow apps to read Messages content without explicit user intent.

Why It Matters
The update addresses growing concern about AI assistants being granted broad, powerful permissions that could expose private communications. It reflects increasing scrutiny of how system-level permissions like Full Disk Access interact with AI agents and user expectations of message privacy.
Key Facts
- Apple action: Announced changes to macOS privacy settings to curb third-party misuse of message access (announcement made Friday).
- Triggering incident: Two weeks earlier, columnist Jason Aten reported that Meta’s Muse sent an unsolicited notification referencing a thread in Apple Messages he had not explicitly granted Muse permission to read.
- Meta's position: Meta CTO David Singleton said Muse can read Messages only if a user grants macOS Full Disk Access and enables a Messages connector in Muse; the integration is opt-in.
- Security expert view: macOS security researcher Patrick Wardle challenged Meta’s assertion, saying Full Disk Access allows reading of non-root files including chats and browsing data.
- Meta PR response: Meta PR reiterated Singleton’s statement that the Messages integration is opt-in and requires both Full Disk Access and the Messages connector to be enabled.
Apple said it will modify macOS privacy settings to prevent third-party developers from abusing system permissions to read users’ message histories. The company announced the change on Friday, citing concerns that some apps could use powerful permissions in ways users do not expect. The announcement followed a report by columnist Jason Aten, who said Meta’s Muse sent him an unsolicited notification that referenced a private Apple Messages thread between him and a co-worker. Aten said he had not granted Muse permission to read his messages and had assumed those conversations were off-limits. The post sparked widespread discussion on social media about the risks posed by AI assistants with access to calendars, emails, messages and other personal data. Meta’s technical lead David Singleton responded by saying Muse’s Messages integration is opt-in: a user must both grant macOS system-level Full Disk Access and enable a Messages connector within Muse for the agent to read Messages content. Meta’s public relations team later reiterated that explanation when asked how Muse could access Messages if Full Disk Access was granted to the app. Not everyone agreed with Meta’s characterization. macOS security researcher Patrick Wardle told the reporter that, from a technical perspective, Full Disk Access can permit reading of many non-root files — including chats, browser histories and cookies — which raised questions about how system-level permissions are managed and whether they can be constrained to prevent unintended data access. Apple’s stated changes aim to tighten those controls and reduce the potential for AI agents or other third-party apps to leverage broad system privileges to access message data without clear, intentional user consent. The episode has brought greater attention to how operating system permissions intersect with AI features and user expectations of privacy.
Keep Reading

Amazon’s $1B plan to combat data center backlash draws more backlash

Apple will limit Mac disk access as AI agents ‘substantially’ increase risk

Netflix is pivoting away from prestige
