Overview
- Apple published a developer announcement on October 2 warning Full Disk Access can expose files, Mail, Messages and browsing history and saying future grants will demand very explicit user action.
- The change was prompted by reports that desktop AI agents and apps may read and act on sensitive local data, including a report about Meta’s Muse and a Wired story about a flaw in ChatGPT’s Mac app, with Meta publicly disputing the Muse claim.
- Apple stressed Full Disk Access was designed for legitimate uses like backups but did not say how backup and system utilities will be accommodated, leaving short-term uncertainty for developers and vendors that rely on broad access.
- Security and developer guidance published since the announcement urges least-privilege design, narrow folder-scoped requests, clear in-app explanations and activity logs, and defenses against prompt-injection and data leaks.
- Beyond the permission change, the debate raises a deeper issue: as agents gain authority to act on data, operating systems may need controls that limit both what software can read and what it can do with that access.