Apple said Oct. 2 that it will add new controls to Full Disk Access, the macOS permission that bypasses almost every privacy safeguard on the system at once -- letting a granted app read files, mail, messages and browsing history, across every account on the machine. The company's own developer announcement was blunt about why now: "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," and Apple said it wants to ensure that access is granted only through "very explicit user action" going forward.
That is a notable thing for a platform vendor to say about its own developer ecosystem. Apple's statement names the problem directly: "some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems ... without users' full knowledge and understanding." (Full Disk Access has existed on macOS for years, mostly granted to backup tools and antivirus software that genuinely need it. The new risk Apple is naming isn't the permission itself -- it's a new category of app asking for it.) Apple did not say when the new controls will ship, or what the revised consent screen will actually look like; the announcement commits to a direction, not a date.
What's changing, and what isn't yet
- What changes
- Full Disk Access will require "very explicit user action" to grant
- Why, per Apple
- AI-agent risk to this access level "will grow substantially"
- Rollout date
- Not disclosed
- Named incidents prompting it
- Meta's Muse (disputed) and a patched ChatGPT for Mac flaw
The incident most directly behind Apple's announcement is still disputed between its two parties. Tech columnist Jason Aten reported that Meta's Muse agent had synced roughly 187,000 lines from his private Messages database -- despite, he says, declining to enable that access during setup -- and that Muse referenced specific private conversations unprompted, including a message from his editor about a deadline. Meta disputes the account. Communications VP Andy Stone said Muse needs both Full Disk Access and its separate Messages connector enabled to read Messages at all, and Meta Superintelligence Labs executive David Singleton said the access sits behind three separate app and macOS protection steps that "a Muse bug cannot bypass." Aten maintains he never flipped the switch Meta says is required, and that Meta has not answered his specific question of how his settings came to show it enabled.
The second incident is less disputed because it has a patch and a tracking number. A vulnerability in OpenAI's ChatGPT for Mac app, assigned CVE-2026-100754, let unprivileged code on a machine impersonate trusted OpenAI components after being invoked in a specific sequence -- at which point the main app process treated the request as legitimate. Security researcher Patrick Wardle found that the app stored chat history locally in plain text rather than encrypted storage, and because the app bypassed Apple's own sandboxing, any other process on the machine could potentially read those logs. OpenAI shipped a fix in app version 26.924.20706 after Wardle's disclosure.
Two AI desktop apps, two different Full Disk Access problems
| ChatGPT for Mac OpenAI | Muse Meta | |
|---|---|---|
| What was reported | A spoofing flaw (CVE-2026-100754) letting untrusted code impersonate trusted app components | A journalist's private Messages allegedly synced without his consent |
| Disputed? | No -- acknowledged and patched | Yes -- Meta disputes the account |
| Resolution | Fixed in app version 26.924.20706 | Unresolved; Aten says Meta hasn't answered his follow-up questions |
“Full Disk Access largely bypasses controls designed to safeguard users' private data.” — Apple Developer News, Oct. 2, 2026
Apple's own framing treats these as a symptom rather than the whole disease. Full Disk Access on macOS has existed for years as a blunt, one-time grant -- a user clicks through a single dialog once, and the app keeps that access indefinitely, with no renewed prompt and no visibility into what it actually reads afterward. That design made sense for the kind of app that traditionally asked for it: a backup tool or antivirus scanner that needs broad access precisely because it runs once and checks everything. An always-on AI agent asking for the same blanket grant is a different request wearing the same permission dialog -- it isn't scanning once, it's reading continuously, and the current system gives a user no way to tell the difference at the moment they click "Allow."
- Requests Full Disk Access during setup, often bundled with a feature-specific connector
- Grants access via a single macOS dialog
- Treats the grant as indefinite -- no renewed prompt, no per-use visibility into what was read
- Add a step requiring "very explicit user action" before the grant takes effect -- mechanism and timing not yet specified
Apple's own statement names a second product alongside Muse: OpenAI's Dots, its always-on agent, gets cited in the same breath as an example of the category Apple is worried about -- not because Dots has its own disclosed incident, but because "always-on" and "autonomous" are the two words Apple's statement keeps returning to. The pattern Apple is naming isn't a complaint about any one company's engineering. It's a bet that the number of agents asking for this exact permission is about to multiply faster than macOS's decade-old, one-dialog-forever model of consent can handle safely -- and that the two incidents already on the record, one disputed and one patched, are the early edge of that curve rather than its full extent.
The person actually exposed in both incidents is not the Mac owner who clicked "Allow" -- it's whoever that owner was messaging. Aten's complaint wasn't only that Muse read his own words; it was that the agent surfaced a private line from his editor, a third party who never consented to anything and has no settings screen of their own to check. The same asymmetry runs through the ChatGPT flaw: a plain-text chat log readable by any other process on the machine exposes not just the user's own prompts but anyone and anything referenced inside them. Full Disk Access was always a request to trust one app with everyone a user talks to, not just the user -- Apple's announcement is the first time that's been named as the actual stake, rather than framed as a single user's personal privacy tradeoff.
What Apple has not done yet is the part that would actually test whether this works: specify whether the new friction is a single clearer dialog (easy to click through just as fast) or something that forces a user to actually understand what they're granting before an agent gets system-wide read access. Until Apple says more, the announcement is a commitment to direction, backed by one disputed incident and one patched one -- real enough to name publicly, not yet detailed enough to evaluate.
- Apple said Oct. 2 it will require "very explicit user action" before granting macOS's broadest system permission, Full Disk Access.
- Apple named AI agents directly, warning the risk from this access level "will grow substantially" as agents get more autonomous.
- The move follows journalist Jason Aten's disputed report that Meta's Muse synced his private iMessages -- Meta says that requires two separate steps a bug can't bypass.
- A separate, now-patched flaw (CVE-2026-100754) let untrusted code impersonate OpenAI's own ChatGPT for Mac app to read local chat logs stored in plain text.
- Caveat: Apple hasn't said when the new controls ship or what the new consent screen will actually look like.