Apple announced changes to macOS Full Disk Access permissions to prevent misuse by AI agents, following reports of unauthorized message access by Meta's Muse app. The company said some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.
The changes come after a controversy involving Meta’s AI assistant Muse, which allegedly accessed private messages without explicit user consent. Tech columnist Jason Aten claimed Muse sent him an unsolicited notification referencing a thread with a co-worker, despite never granting the app access to his messages.
Meta’s CTO, David Singleton, defended the app, stating that Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled. However, security expert Patrick Wardle questioned this stance, arguing that with Full Disk Access, any non-root file is readable, including browsing history and chats.
Apple’s announcement follows a series of security concerns, including a disclosed Muse configuration that allowed any app or code on a Mac to take full control of the AI assistant. This, along with Amazon’s decision to block Muse, suggests the app may not be worthy of the access it requires to function as described.
Apple did not name Meta or Muse specifically, but the timing of the announcement—following a major social media uproar—suggests a possible connection to the Muse incident. The company emphasized the need for users to understand the risks before granting such access.
Source: arstechnica