Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action.
Apple announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.
Wardle has also been acknowledged for reporting another vulnerability , tracked as CVE-2026-100754 , impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.
It's currently not known when the new controls will be rolled out.
These findings demonstrate how the privileged position enjoyed by agentic tools, the extensive data they collect , and their ability to interact with various parts of the operating system, like writing files to disk, accessing the mic and camera, creating calendar events, sending emails, and monitoring location, can expand the attack surface and open the door for an adversary to abuse this access and steal sensitive data.
Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Access and have a Messages connector setting in Muse enabled.
This option is essential for apps, such as security tools and backup software, that require deep system access to function properly.
Once the setting is enabled for an application, it allows that program to bypass certain security restrictions and read and write to system files that apps are typically restricted from accessing or modifying.
The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said.
Muse is advertised as a "personal AI agent" built along the lines of OpenClaw that runs on a dedicated Linux virtual machine on Meta's cloud.
What happened
Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action.
Apple announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.
What changed
Wardle has also been acknowledged for reporting another vulnerability , tracked as CVE-2026-100754 , impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.
It's currently not known when the new controls will be rolled out.
Who is affected
These findings demonstrate how the privileged position enjoyed by agentic tools, the extensive data they collect , and their ability to interact with various parts of the operating system, like writing files to disk, accessing the mic and camera, creating calendar events, sending emails, and monitoring location, can expand the attack surface and open the door for an adversary to abuse this access and steal sensitive data.
Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Access and have a Messages connector setting in Muse enabled.
Why it matters
This option is essential for apps, such as security tools and backup software, that require deep system access to function properly.
Once the setting is enabled for an application, it allows that program to bypass certain security restrictions and read and write to system files that apps are typically restricted from accessing or modifying.
Technical details
The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said.
What remains unknown
It's currently not known when the new controls will be rolled out.
Attribution
The Hacker News: Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.
What to watch next
Watch for updated vendor guidance and fixed-version details.