Every score is worked out from the vendor's own pages · How we score →Disclosure
SAASINSPECTOR
Oct 2, 2026

Apple to tighten Mac Full Disk Access as AI agents raise risk

Apple says new controls will require very explicit user action, after a Meta Muse dispute and a patched ChatGPT Mac app flaw.

Apple to tighten Mac Full Disk Access as AI agents raise risk

Apple has announced that it is introducing additional controls around Full Disk Access on macOS. The setting was designed to let backup apps work properly, and Apple says AI agents have increased the risks associated with this level of access. Apple has not said when the update will arrive.

What Apple said

In a post aimed at developers, Apple said that some developers are using Full Disk Access in ways that could put users at risk, exposing files, mail, messages and even browsing history without users' full knowledge and understanding. Going forward, users who genuinely wish to grant an app this extraordinary level of access will be able to do so only with "very explicit user action". Apple added that as AI agents become more capable and autonomous, the risks "will grow substantially".

The Meta Muse dispute

The announcement came days after Inc. columnist Jason Aten reported that Meta's Muse AI knew the contents of his private messages, even though he said he had not given it permission. Meta spokesperson Andy Stone disputed this, saying access to Messages is entirely opt-in and that you have to enable both Full Disk Access and the Messages connector for Muse to read your Messages content.

The ChatGPT Mac app flaw

Wired reported a vulnerability in the macOS version of ChatGPT, found by researchers at the Objective-See Foundation and now patched. OpenAI acknowledged the flaw and fix in its system change log on September 25. The app checks digital signatures at three layers so that only OpenAI components talk to each other. Researcher Patrick Wardle found a trusted script interpreter that would accept an untrusted script, and a malicious script could spawn the interpreter three times to satisfy the checks. His proof of concept needed about a dozen lines of code.

Three wax seals on a cord with the middle seal cracked and a rolled scroll slipping through, for the signature check flaw in ChatGPT's Mac app.
Three wax seals on a cord with the middle seal cracked and a rolled scroll slipping through, for the signature check flaw in ChatGPT's Mac app.

An attacker could have read all chat logs and other stored data, reached connected browser sessions, and had ChatGPT run commands that looked like legitimate instructions from the app. The flaw could only be exploited by an attacker who already had malware on the machine.

Wardle also found a now patched flaw in the dictation feature of Meta's Muse, which a local attacker could have used to grab a mishandled authentication token. He has submitted a new finding to OpenAI about the integration between ChatGPT and its always-on Dots assistant, which OpenAI is reviewing. He plans to present analysis of several AI macOS app bugs at Objective by the Sea in November.

Why it matters

Wardle compares AI agents to a building manager with the keys to all the rooms: "if they can be corrupted or subverted, that's super problematic." He says AI companies are fixated on adding features, and that more features mean a broader attack surface. Apple's change deals with how clearly users consent. It does not fix bugs in the apps that hold the access.

What to check on your Mac

Review which apps hold Full Disk Access in your Mac's privacy settings, including any AI desktop agent. Keep the ChatGPT Mac app updated so the patch is in place, and revoke access you did not knowingly choose to give.

Sources
Tools mentioned