Apple moves to strengthen macOS security permissions
Apple plans to add stronger security controls to macOS's "Full Disk Access" permission as the growing use of AI agents raises new privacy concerns, the company said in a developer notice on Oct. 2 local time.
Full Disk Access was originally designed for applications such as backup tools that need broad access to system data. Apps with this permission can view files stored on a Mac, as well as sensitive information such as emails, messages and web browsing history.
Apple said the risks associated with the permission are increasing as AI agents become more capable of acting on behalf of users by reading files and controlling applications.
Company warns about unclear risks of broad access
Apple said some developers may be exposing a user's entire system in ways users do not fully understand, creating security risks. The company argued that people should have a clearer understanding of how far a permission extends and what risks come with approving it.
The company also noted that the impact may extend beyond the device owner. For example, if a messaging application receives this level of access, information belonging to other people in conversations could also be affected.
Apple said the increasing capability and autonomy of AI agents will likely make access-related risks more significant because these tools can perform more tasks independently than traditional applications.
New approval process planned, timing not disclosed
Apple said it intends to require users to take a more explicit action before granting unusually high levels of system access. When an app requests Full Disk Access, users will be asked to review the scope of the permission and provide a clearer approval.
The company has not disclosed the exact form of the new approval process or when the changes will take effect.
AI agent privacy debates continue
The announcement comes amid wider debate over desktop AI agents and their access to personal information. OpenAI added an optional feature to the Mac version of ChatGPT in August that can read and summarize conversations in Apple's Messages app and help users draft and send messages. The feature requires Full Disk Access, which led to discussions about privacy and security risks.
Meta's AI agent Muse has also faced scrutiny. A U.S. columnist claimed Muse knew the contents of personal messages stored on a Mac without permission, a claim Meta denied. Meta said message integration is an optional feature and requires users to manually enable both Full Disk Access and a message connector.
Comments
Post a Comment