Overview
- Apple announced in a Developer post on October 2 that it will add controls so granting Full Disk Access requires “very explicit user action,” noting the permission can expose files, Mail, Messages and browsing history.
- The move responds to recent reporting about desktop AI agents and app flaws, including contested claims that Meta’s Muse accessed private Messages and reporting of a potential flaw in the ChatGPT Mac app that could expose sensitive data.
- Full Disk Access was built to let backup and system utilities read the whole drive but has been requested by many other apps, and Apple says some uses may put users or their contacts at risk.
- Apple says users who genuinely need Full Disk Access will still be able to grant it, yet developers and power users face uncertainty because Apple has not released how the new approval flow will work or when it will appear.
- Security experts and developer guidance recommend narrowing scopes, showing clear, in‑app explanations, logging activity, and treating local files as untrusted input to harden agents against prompt injection and data leaks.