Apple Tightens macOS Full Disk Access as AI Agents Become More Powerful

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Apple plans to add stronger controls to Full Disk Access in macOS, warning that the powerful permission can expose a user’s most private data as AI agents become more capable. The company said the change will require users to take a far more deliberate action before granting an app this broad level of access.

Full Disk Access was built to help trusted Mac tools, mainly backup software, work around normal privacy limits when needed. However, the permission can let an app reach files across the Mac, along with data held by Mail, Messages, Safari, Home, Time Machine backups, and certain system settings.

Apple’s current guidance already treats the setting as a high-risk permission, requiring users to manually add an app through the Privacy & Security section of macOS settings.

Apple Tightens macOS Full Disk Access

Apple said some developers are using Full Disk Access in ways that may leave users unaware of how much information an app can see. The concern is not limited to documents stored on the device.

A granted app may be able to access email, private chats, browsing history, and other personal records that are normally protected by macOS controls. For communication tools, the privacy impact can also extend to other people involved in those conversations.

The growing use of AI agents makes this issue more serious. Unlike a normal app that performs one clear task, an AI agent may read information from several sources, process it, and take further actions based on what it finds.

Broad disk access could therefore give an agent visibility into a large amount of personal or business data. Apple said the risks will grow substantially as these tools become more capable and act with greater independence.

Apple has not yet shared the exact design, release date, or supported macOS versions for the additional controls. Still, its wording suggests the company wants to move beyond a simple permission toggle and make users clearly understand the scope of access before enabling it.

The change does not appear to remove Full Disk Access from legitimate backup, security, or recovery tools. Instead, it aims to make sure people consciously approve an exceptional permission rather than enabling it while rushing through an app setup process.

For Mac users, the immediate step is to review the existing list of apps with Full Disk Access. Open System Settings, select Privacy & Security, and then choose Full Disk Access.

Remove access for tools that are no longer used or that do not have a clear need to read data from across the system. This is particularly important for desktop AI assistants, browser extensions, system cleaners, and communication apps.

The move also follows wider concern about weaknesses around macOS Transparency, Consent, and Control protections. Cyber Security News recently reported on a macOS TCC bypass vulnerability and on the growing risks of AI agents carrying out ransomware activity.

Apple’s planned update shows that strong permission design is becoming a key security control as AI software gains deeper access to user devices.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Apple Tightens macOS Full Disk Access as AI Agents Become More Powerful appeared first on Cyber Security News.