Apple announced changes to macOS full-disk access (FDA) permissions to prevent third-party AI agents from abusing system-level file access, following controversy over Meta's Muse assistant. The incident began when technology columnist Jason Aten reported that Muse sent an unsolicited notification referencing a private Apple Messages thread he had not authorized the agent to read. Meta CTO David Singleton responded that Muse requires two explicit user actions: granting macOS system-level FDA and enabling the Messages connector within the Muse Mac application, asserting the integration is opt-in. However, macOS security researcher Patrick Wardle challenged this characterization, noting that FDA technically permits any application to read all non-root files, including browser history, cookies, and chat databases such as those used by Messages. When pressed on why Muse could not access messages under FDA while other applications with the same privilege can, Meta reiterated Singleton's statement without addressing the technical discrepancy. Apple's forthcoming modifications aim to restrict how FDA is granted or utilized by AI-driven applications, though specific implementation details were not disclosed. The episode underscores the tension between granular user consent models and the broad filesystem access inherent in FDA, particularly as autonomous agents request elevated privileges to operate across calendars, email, and messaging platforms.

Read original