What happened

Apple has said it will tighten the controls around Full Disk Access, a macOS setting that grants an application broad reach across a user's files, mail, messages and browsing history. In a post aimed at developers, the company said some developers are using the permission in ways that could put users at risk and expose what is on their systems without users fully understanding what they are approving.

Full Disk Access largely bypasses the privacy controls Apple built around user data. Apple said it plans to change the setting so that this kind of access is granted only through an explicit user action. It has not said when the new controls will arrive. The company framed the change around AI agents in particular, noting that as those agents become more capable and autonomous, the risks attached to that level of access will grow substantially.

The announcement follows reporting that Meta's Muse agentic tool read a journalist's private iMessages, and follows security researcher Patrick Wardle's published proof of concept for a Muse flaw he called not-a-mused. Wardle has also been credited for a vulnerability tracked as CVE-2026-100754 in OpenAI's ChatGPT application for macOS.

Why this is a GRC story

Agents inherit permissions, and permissions outlive intent. An assistant that can read everything on a laptop is convenient by design, and that design choice is a governance decision even when nobody wrote it down as one. The permission is granted once at setup and then exercised continuously by software the user did not write and rarely inspects.

Consent without comprehension is not consent. Apple's own wording makes the point: the risk is exposure without the user's full knowledge and understanding. A prompt that says a tool needs access to files is a poor proxy for telling someone that the tool will read their messages and browsing history.

The endpoint is part of the AI supply chain. Desktop agents pull updates, reach remote services and act on local data. If an asset register still treats laptops as static devices and a vendor risk process only looks at SaaS contracts, the review will not cover what is actually running on the machine.

What to watch

Watch the wording Apple eventually puts in the consent prompt, because that wording becomes the baseline users and auditors expect to see elsewhere. Watch, too, for enterprise guidance on which agentic tools staff may run locally and at what access level.

There is useful work available in the meantime. An access review that lists every application and agent holding Full Disk Access, names an owner for each, and records the business reason for the permission is a reasonable half day of effort, and it produces something an auditor can actually read.

Attribution: Analysis based on The Hacker News and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News