Apple Tightens "Full Disk Access" Permission on macOS in Light of AI Agent Security Concerns

Apple Tightens "Full Disk Access" Permission on macOS in Light of AI Agent Security Concerns

Apple released a blog post on their Developer website announcing that they plan on tightening security around the "Full Disk Access" permission on macOS in light of AI agents misusing it and putting user data at risk.

The post explains that the permission is meant to facilitate backups for your Mac, but developers are using it in a way that jeopardizes sensitive personal data:

We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

They say they won't remove Full Disk Access completely, but will provide more controls so that "very explicit user action" is needed before it's granted, and the risks of allowing FDA are made clear:

Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.

It's interesting that they explicitly call out AI agents as particularly dangerous. Not long after Meta's launch of its Muse AI agent, Muse made headlines for its privacy issues.

Those unfortunate enough to have given it full access to their device found it had breached their privacy. In one instance, it read someone's private messages, despite them explicitly denying the app permission to read their messages.

In another, it had accrued a ton of data about complex interpersonal relationships.

Meta boasted about the supposed privacy and security properties of its Muse AI, particularly its Sentinel that's meant to ask approval and prevent unintended actions from being performed.

Yet these agents still access tons of data in order to build their "personal context" about you. Muse wants you to connect your bank account, email, and everything about you in order to be a more helpful personal assistant. That level of access is going to be dangerous for any program, let alone an autonomous agent that can act on its own.

Community Discussion