Saturday, October 3, 2026
Tech Beat
Oct 2, 2026, 11:03 PMCybersecurity

Apple Tightens macOS Full Disk Access as Meta Muse Raises AI Privacy Risks

Apple plans tighter macOS Full Disk Access controls after Meta's Muse AI exposed privacy risks involving Messages, files, mail and browsing history data.

Listen to this briefingAudio briefing

Summary

On October 2, 2026, Apple said it will revise macOS Full Disk Access after warning that some developers use the permission without users fully understanding that it exposes files, mail, messages and browsing history. The announcement followed Jason Aten’s claim two weeks earlier that Meta’s Muse sent an unsolicited notification referencing an Apple Messages thread with a coworker, despite Aten believing he had never authorized message access. The incident triggered widespread criticism of AI assistants connected to communications, calendars, email and shopping accounts.

Meta CTO David Singleton said Muse can read Messages only when users manually grant Full Disk Access and enable its opt-in Messages connector. Security researcher Patrick Wardle countered that Full Disk Access already lets an app read any non-root file, including chats, cookies and browsing history. Apple did not name Meta or Muse, and no other apps are known to have misused the permission this way, but warned that increasingly autonomous AI agents magnify risks to users and their contacts. Eleven days earlier, Wardle disclosed a Muse configuration allowing any Mac app, code or ClickFix-injected command to control the assistant and access its resources. Amazon has blocked Muse, saying such apps must operate openly and respect providers’ participation decisions. Apple provided no rollout details, while Meta did not answer Friday’s questions.

Positives

  • October 2, 2026, Apple committed to revising Full Disk Access so users better understand its extensive privacy consequences.
  • Two manual approvals, Full Disk Access and the opt-in Messages connector, are required under Meta’s stated Muse configuration.
  • Apple’s warning explicitly recognizes that broad app permissions can also compromise the privacy of users’ contacts.
  • Amazon blocked Muse while demanding that AI agents operate openly and respect service providers’ participation choices.

Risks & concerns

  • Jason Aten said Muse referenced a private Apple Messages thread despite his belief that he had never authorized message access.
  • Full Disk Access lets apps read non-root files, potentially exposing chats, browser cookies, mail, files and browsing history.
  • Eleven days before Apple’s announcement, Patrick Wardle showed that apps, code and ClickFix commands could seize control of Muse.
  • Meta’s permission explanation conflicts with concerns that Full Disk Access itself enables message access, regardless of Muse’s connector setting.
  • Apple disclosed no technical design or rollout date for its planned macOS privacy changes.
  • Meta did not answer questions sent Friday about whether Muse could read Messages through Full Disk Access alone.
Primary sourceAI - Ars Technicahttps://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityOct 2

Apple Tightens macOS Full Disk Access as AI Agent Privacy Risks Grow

CybersecurityOct 2

Epic Pauses Development After AI Finds MyChart Security Flaws

CybersecurityOct 1

Kevin Mandia’s Armadin Raises $255.5M at Over $2.5B Valuation