Overview
- Apple announced in a Developer News post on October 2 that it will add new controls so Full Disk Access can be granted only through much more explicit user action.
- Full Disk Access is a macOS setting that lets apps bypass normal privacy protections to read or modify protected data stores used by Mail, Messages, files and browsing history, a level of access Apple says some developers have misused.
- The move follows reporting that Meta’s Muse reportedly accessed a journalist’s Messages and security research showing proof‑of‑concept exploits and a CVE affecting Mac agent apps, which highlighted how agentic software can expand the attack surface.
- Apple has not said when the changes will roll out, whether existing apps will lose current permissions, or how backup utilities and Apple’s own AI features will be treated, leaving developers and users uncertain about compatibility and workflow changes.
- Security experts and developers say best practices are to request narrower, least‑privilege access, show clear prompts and activity logs, and avoid sending unnecessary local data off‑device so users can understand and control what agents can do.