DKDKCISSPSearch
AI Security

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

DKCISSP News DeskThe Hacker News5 Oct 2026, 4:08 pm
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action.

Apple announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

Wardle has also been acknowledged for reporting another vulnerability , tracked as CVE-2026-100754 , impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.

It's currently not known when the new controls will be rolled out.

These findings demonstrate how the privileged position enjoyed by agentic tools, the extensive data they collect , and their ability to interact with various parts of the operating system, like writing files to disk, accessing the mic and camera, creating calendar events, sending emails, and monitoring location, can expand the attack surface and open the door for an adversary to abuse this access and steal sensitive data.

Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Access and have a Messages connector setting in Muse enabled.

This option is essential for apps, such as security tools and backup software, that require deep system access to function properly.

Once the setting is enabled for an application, it allows that program to bypass certain security restrictions and read and write to system files that apps are typically restricted from accessing or modifying.

The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said.

Muse is advertised as a "personal AI agent" built along the lines of OpenClaw that runs on a dedicated Linux virtual machine on Meta's cloud.

What happened

Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action.

Apple announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

What changed

Wardle has also been acknowledged for reporting another vulnerability , tracked as CVE-2026-100754 , impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.

It's currently not known when the new controls will be rolled out.

Who is affected

These findings demonstrate how the privileged position enjoyed by agentic tools, the extensive data they collect , and their ability to interact with various parts of the operating system, like writing files to disk, accessing the mic and camera, creating calendar events, sending emails, and monitoring location, can expand the attack surface and open the door for an adversary to abuse this access and steal sensitive data.

Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Access and have a Messages connector setting in Muse enabled.

Why it matters

This option is essential for apps, such as security tools and backup software, that require deep system access to function properly.

Once the setting is enabled for an application, it allows that program to bypass certain security restrictions and read and write to system files that apps are typically restricted from accessing or modifying.

Technical details

The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said.

What remains unknown

It's currently not known when the new controls will be rolled out.

Attribution

The Hacker News: Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

What to watch next

Watch for updated vendor guidance and fixed-version details.

MORE IN AI SECURITY

More cybersecurity reporting

The State of Cybersecurity in 2026: Key Segments, Insights, and InnovationsThe Hacker News · 3 Oct 2026, 4:30 pmGitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pm