
AI NEWS
Apple changes full-disk access permissions to curb abuse from AI agents
Apple is updating macOS privacy settings to restrict third-party AI agents from accessing sensitive data like message histories without explicit, granular consent. This move follows a controversy involving Meta's Muse AI agent, which appeared to read user messages despite claims that access was opt-in. The incident highlighted the risks of broad 'full-disk access' permissions, prompting Apple to tighten controls and prevent misuse by powerful AI tools.
THE NEWS
What happened
Apple is updating macOS privacy settings to restrict third-party AI agents from accessing sensitive data like message histories without explicit, granular consent. This move follows a controversy involving Meta's Muse AI agent, which appeared to read user messages despite claims that access was opt-in. The incident highlighted the risks of broad 'full-disk access' permissions, prompting Apple to tighten controls and prevent misuse by powerful AI tools.
CONTEXT
Why it matters
Apple is rolling out critical privacy updates for macOS to prevent AI agents from abusing 'full-disk access' permissions. Following a controversy where Meta's Muse AI seemed to read private messages, Apple is now requiring more granular user consent before sensitive data like chat histories can be accessed. This shift addresses growing concerns about how powerful AI tools might exploit broad system permissions to harvest personal information without clear, specific authorization.
AT A GLANCE
Key facts
- Apple is modifying macOS full-disk access permissions to curb potential abuse by third-party AI agents.
- Meta's Muse AI agent was accused of reading a user's Messages history without clear consent.
- Meta CTO David Singleton claimed Muse required both Full Disk Access and an enabled Messages connector to read content.
- Security expert Patrick Wardle argued that Full Disk Access allows any app to read nearly all non-root files, including chats and cookies.
- Apple's new changes aim to ensure AI agents cannot access sensitive data unless users grant specific, narrow permissions.
SOURCE
Original source
This article is based on information published by Ars Technica AI.



