Apple to Tighten Full Disk Access Rules for Mac Apps
Apple will update macOS to require users to take more explicit action before apps receive Full Disk Access, citing potential user risk.

Apple announced on October 2 that it will update macOS to require users to take more explicit action before applications, including AI agents, can receive Full Disk Access. The company stated that some developers were using this permission in ways that could put users at risk.
On macOS, applications are sandboxed by default. Full Disk Access allows software to read protected data from other applications, such as Mail, Messages, Safari, backups, and certain system files. This permission grants deep access to a user's data.
The change follows criticism leveled at Meta's Muse, an AI agent that could connect to user data sources through optional integrations. Meta confirmed that Muse could only access Apple Messages if users explicitly enabled both Full Disk Access and its "Messages connector."
Security researchers have previously documented multiple methods by which attackers could bypass macOS privacy controls, either accidentally or intentionally. These new restrictions aim to enhance user data security and control.