AI Agents Turn macOS Full Disk Access Into a Privacy Risk
Summary
The article examines how macOS privacy controls are being challenged by AI agents that can act on a user’s behalf. macOS distinguishes between files a user explicitly opens and locations that apps access independently, but Full Disk Access remains a broad permission covering sensitive areas of the home folder, including Messages and Mail. It is commonly granted to Terminal and backup utilities because narrower controls may prevent them from performing legitimate tasks. Newer agents such as Meta’s Muse, along with ChatGPT agents and Microsoft Copilot assistants, seek access to local files and applications so they can interpret goals and carry out actions. Meta says Muse can read information from apps such as iMessage, Notes, Reminders, Email, and Calendar, while also acknowledging that agents may be inaccurate or take unexpected actions and that users are responsible for the results. The article highlights prompt injection as an inherent risk: external content can be crafted to redirect an agent from its original goal. Muse has also had security vulnerabilities reported, and its activity logs are less detailed and auditable than Apple Intelligence Reports. Apple is expected to refine Full Disk Access, but the article argues that simply adding more settings may further confuse users. Its recommendation is to avoid granting Full Disk Access to third-party AI agents until Apple has addressed the privacy problem more fully.