Apple Tightens Full Disk Access: What Mac Users Should Check

Aufgeklappter Laptop mit Schloss-Symbol als Sinnbild für Datenschutz
Photo by FlyD on Unsplash

Apple plans to make the most far-reaching permission in macOS harder to grant. Full Disk Access lets an app read practically everything on a Mac, from documents to mail to message history. In a notice to developers, Apple explicitly ties the move to AI agents: the more capable and autonomous they become, the greater the risk of this level of access. For Mac users, it is a good reason to review their own list of approved apps right now.

Key takeaways

  • On October 2, Apple announced additional controls: going forward, Full Disk Access should only be grantable through “very explicit” user action.
  • Apple’s reasoning: some developers use the permission in ways that expose files, mail, messages, and browsing history without users’ full understanding, and AI agents make the problem worse.
  • Apple has not given a timeline or a macOS version.
  • The backdrop includes a disputed case involving Meta’s AI agent Muse and a now-fixed flaw in the ChatGPT app for Mac.
  • To check which apps currently have full access, look under System Settings, Privacy & Security.

What Apple announced

The notice on Apple’s developer site is short but pointed. Apple says it gives developers powerful APIs backed by controls designed to protect users’ private data. Full Disk Access largely sidesteps those controls so that backup apps can work on the Mac. But some developers are using the permission in ways that could put users at risk, exposing everything on their systems, including files, mail, messages, and even browsing history, without users’ full knowledge and understanding. For communication apps, Apple adds, this can also compromise the privacy of the people users are talking to.

Going forward, Apple will introduce additional controls so that only users who genuinely want to grant this access can do so, and only through very explicit user action. Apple sums up its core reasoning this way: as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. The notice does not say what the new controls will look like or which macOS version will introduce them. Apple did not respond to a request for comment from TechCrunch.

Why this permission is so sensitive

Apple’s own support pages describe what Full Disk Access means: access to all files on the computer, including data from other apps such as Mail, Messages, Safari, and Home, Time Machine backups, and certain administrative settings for all users of the Mac. Normally an app has to ask separately for each of these areas. Full access removes that fine-grained control.

For traditional software, the risk was manageable, because a backup app does what it was built to do. An AI agent, by contrast, decides for itself which files to open, and in the worst case can be steered by booby-trapped content into actions nobody asked for. There is also a macOS quirk that matters for command-line agents. When a program is launched in Terminal, the permission check treats Terminal as the responsible app. An Apple engineer put it succinctly on the developer forums: for a tool run by the user from Terminal, the tool’s responsible code is Terminal. So anyone who gives Terminal full access is effectively giving it to every program that runs inside it, including an AI agent.

The cases in the background

Apple names no names, but TechCrunch points to two incidents from the past few days. The first involves Meta’s AI agent Muse, whose shopping features and dispute with Amazon we have covered before. Inc. columnist Jason Aten wrote that Muse synced roughly 187,000 lines from the Messages database on his Mac mini, even though he had declined Messages access during setup and left Full Disk Access turned off.

Meta disputes the account. David Singleton of Meta Superintelligence Labs said the Messages integration in the Mac app is opt-in and requires three separate permissions that macOS would not let an app bypass even with a bug. Meta spokesperson Andy Stone said Muse can only read Messages if both Full Disk Access and the Messages connector inside Muse are turned on. How Muse nonetheless got to the messages in Aten’s case has not been explained so far.

The second case involves OpenAI’s ChatGPT app for Mac. Security researchers at the Objective-See Foundation, led by Patrick Wardle, found a flaw that let an attacker take over the app on a victim’s machine and access the conversation history and connected services. The check on which processes were allowed to send the app commands could be fooled with a few lines of code. OpenAI says it fixed the flaw on September 25 and acknowledged that it needs to move faster on security. Wardle sees a broader pattern: AI companies are fixated on adding features right now, and more features mean a broader attack surface.

What Mac users can do now

Until Apple ships the new controls, users can check their own setup in a few clicks. Under the Apple menu, System Settings, Privacy & Security, there is an entry called Full Disk Access. The list shows every app that can currently read everything. Backup software and some security tools genuinely need that access. For assistant apps, chat clients, and agents, it is worth asking whether they really need it or whether targeted permissions would do, for example under Files & Folders for the Desktop, Documents, and Downloads folders.

Anyone who uses command-line agents should pay particular attention to Terminal. If it has full access, that access applies to every agent working inside it. A better approach is to grant Terminal full access only temporarily for a specific task and revoke it afterward, or to let agents work in a dedicated project folder without access to mail and messages.

Outlook: agents need finer-grained permissions, not blanket ones

Apple’s move stands out because it re-evaluates a permission that predates AI agents. Full Disk Access was meant as an exception for backups and has become a shortcut for software that wants as much context as possible. Agents in particular become more useful the more they know about their users, and that is exactly why Apple is drawing a line here. What will matter is whether the new controls amount to more than one more warning dialog that people click away by reflex. The better answer for agents lies in fine-grained permissions that open exactly the folder or mailbox a task needs, not the whole computer. Anyone who cleans up their list today will already be prepared.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top