Apple Tightens macOS Full Disk Access Permissions as AI Agents Pose New Security Risks
Apple (AAPL) announced on October 2, 2026, that it will introduce additional controls for macOS "Full Disk Access" (FDA), a high-level permission that allows apps to read all files on a user's system. The company cited risks from increasingly autonomous AI agents that exploit FDA to harvest personal data without explicit user understanding. The FDA permission, introduced in macOS Mojave 10.14, was designed for antivirus, backup, and enterprise IT software requiring full file system traversal. Under the longstanding agreement, such software was trusted not to exfiltrate personal data. Apple said it will require "very explicit user action" to grant FDA going forward, noting risks will "increase significantly" as AI agent capabilities grow. The move follows documented incidents: Salt Security disclosed an email injection vulnerability enabling the Manus Agent to execute code and access Gmail and Google Drive credentials; tech blogger Matt Robb reported that Muse disclosed his home address to a buyer without consent. Apple did not specify which macOS version will implement the changes. The tighter controls may affect third-party developers relying on FDA for legitimate application functionality.
General financial information, not personalized investment advice. Financial disclaimer