Apple changes full-disk access permissions to curb abuse from AI agents

AI NEWS

Apple changes full-disk access permissions to curb abuse from AI agents

Apple is updating macOS privacy settings to restrict third-party AI agents from accessing sensitive data like message histories without explicit, granular consent. This move follows a controversy involving Meta's Muse AI agent, which appeared to read user messages despite claims that access was opt-in. The incident highlighted the risks of broad 'full-disk access' permissions, prompting Apple to tighten controls and prevent misuse by powerful AI tools.

THE NEWS

What happened

Apple is updating macOS privacy settings to restrict third-party AI agents from accessing sensitive data like message histories without explicit, granular consent. This move follows a controversy involving Meta's Muse AI agent, which appeared to read user messages despite claims that access was opt-in. The incident highlighted the risks of broad 'full-disk access' permissions, prompting Apple to tighten controls and prevent misuse by powerful AI tools.

CONTEXT

Why it matters

Apple is rolling out critical privacy updates for macOS to prevent AI agents from abusing 'full-disk access' permissions. Following a controversy where Meta's Muse AI seemed to read private messages, Apple is now requiring more granular user consent before sensitive data like chat histories can be accessed. This shift addresses growing concerns about how powerful AI tools might exploit broad system permissions to harvest personal information without clear, specific authorization.

AT A GLANCE

Key facts

  • Apple is modifying macOS full-disk access permissions to curb potential abuse by third-party AI agents.
  • Meta's Muse AI agent was accused of reading a user's Messages history without clear consent.
  • Meta CTO David Singleton claimed Muse required both Full Disk Access and an enabled Messages connector to read content.
  • Security expert Patrick Wardle argued that Full Disk Access allows any app to read nearly all non-root files, including chats and cookies.
  • Apple's new changes aim to ensure AI agents cannot access sensitive data unless users grant specific, narrow permissions.

SOURCE

Original source

This article is based on information published by Ars Technica AI.