Apple has announced plans to change how macOS Full Disk Access is configured so that access to the full contents of the disk is granted only as the result of an explicit, deliberate user action, against the backdrop of incidents where AI agents gained access to private messages and other confidential data. All macOS users are affected, especially those installing apps like Meta Muse and ChatGPT for Mac, and the key practical takeaway right now is to review the list of programs with Full Disk Access and minimize the privileges of AI tools.
Technical details: what Apple is changing and why
The Full Disk Access (FDA) setting appeared in macOS Mojave 10.14 and is managed via the Privacy & Security section in System Settings. It allows an application to bypass the standard restrictions on accessing other apps’ data (Mail, Messages, Safari, Time Machine, etc.) and work with almost the entire contents of the user’s disk. This is critical for backup and some security tools, but dramatically increases the potential damage if such a program is compromised. The official description of the mechanism is available in Apple’s documentation: Full Disk Access guide for macOS.
In a recent message to developers, Apple explicitly states that a number of applications use Full Disk Access in a way that “may put users at risk by opening up the entire contents of the system, including files, mail, messages, and browser history, without the user’s full understanding.” For communication apps, this also affects the correspondence of third parties with whom the user is communicating. The vendor states plans to change the logic so that such access is provided only as a result of a clearly expressed user action, and not indirectly or via non-obvious dialogs. Implementation details and timelines have not yet been disclosed, but the position is fixed in the official announcement: Apple developer announcement.
Apple formulates the main motive for the changes as follows: as AI agents become “increasingly capable and autonomous,” the risks from their operation with full disk access “grow substantially.” In effect, the vendor acknowledges that the combination of (1) very broad operating system–level privileges and (2) autonomous behavior driven by a complex model with external connections changes the macOS threat model.
Meta Muse and ChatGPT for Mac: real incidents around privileged AI agents
Muse: a personal agent with system privileges
Muse from Meta is positioned as a “personal AI agent” running in a dedicated Linux virtual machine in Meta’s cloud and tightly integrated with the user’s working environment. The official product description is available on Meta’s website: Muse page, and the approach to security and access is described in a separate company publication: Muse security and safety overview.
The heightened attention was triggered by a case where, after granting Muse Full Disk Access on a Mac, the agent obtained access to the user’s private iMessage conversations. Meta later clarified that reading messages requires two conditions: (1) Full Disk Access is allowed at the macOS level, and (2) a special Messages connector is enabled within the Muse settings. The Meta CTO emphasized that integration with Messages happens “only when explicitly enabled,” and the agent can read message contents only when both of these conditions are met; see the statement in the Meta CTO’s post.
The incident exposed a systemic problem: even if the vendor honestly documents the integration, the end user is not always able to assess the combined risk from Full Disk Access together with a powerful AI agent that has a network connection and access to the microphone, camera, file system, calendar, etc. The error lies less in the implementation and more in the privilege model.
not-a-mused: how a local process can “ride” an AI agent
A different level of risk was demonstrated by a proof-of-concept research project called not-a-mused, which targeted the Muse client for macOS. The vulnerability (later fixed by Meta) allowed any local process without elevated privileges to obtain an authentication token for the Muse account. Due to an undocumented endo_voyager_dictation_endpoint setting, an attacker could redirect dictation traffic, intercept voice commands and text queries, and also tamper with them, forcing the legitimate AI agent to perform arbitrary actions on behalf of the user.
The researcher’s key conclusion: Muse has significantly broader access to system data and functions than typical local malware; therefore, compromising this particular application turns it into a convenient “bridge” for privilege amplification and large-scale collection of sensitive data.
ChatGPT for Mac and CVE‑2026‑100754
Similar principles were demonstrated by a vulnerability in the official ChatGPT for macOS application, tracked as CVE‑2026‑100754. According to the CVE description, an implementation flaw could allow an attacker to take over control of the application and gain unauthorized access to chat logs and other data stored by the app. The vulnerability entry is available both on the CVE program website (CVE‑2026‑100754 record) and in the NVD database: NVD details for CVE‑2026‑100754.
OpenAI acknowledged the issue and released an update to the Mac application, as reflected in their changelog: ChatGPT app changelog. Once again, the combination of a vulnerable AI client that stores large volumes of sensitive data plus elevated system privileges turns the application into a high-value target.
Threat context: the privileged AI agent as a new “risk concentration point”
Both Meta and independent researchers emphasize that AI agents occupy a privileged position in the user ecosystem: they have broad access to data, can create and modify files, and interact with the calendar, email, geolocation, and other services. Meta’s official help center describes the situation in exactly these terms: the agent can act on the user’s behalf using trusted access to the ecosystem; see Meta’s guide on the privileged position of AI tools.
Journalistic investigations further show that tools like Muse build detailed profiles not only of the user themself but also of their environment—friends, family, colleagues—based on correspondence, calendars, and other data sources. Examples of such analysis are described in the Wired article on profiling using Muse data.
Taken together, this means that from a threat perspective an AI agent with Full Disk Access turns into a “centralized hub” of risk: compromising a single application can provide access to all communications, work documents, and the user’s activity history.
Impact assessment: who should be most concerned
The following categories of users and organizations appear most vulnerable:
- Journalists, human rights defenders, political activists — any leak of correspondence, drafts, and contacts from a privileged AI agent creates direct risks to physical and legal safety.
- Corporate macOS users who install AI agents to boost productivity (email processing, meeting minutes, task automation) — a wide range of internal data can be compromised via such applications.
- Developers and technical specialists who use AI tools to work with source code and configurations — an AI agent’s access to repositories and configuration files containing secrets makes it a convenient vector for stealing intellectual property and access keys.
If there is no response, scenarios look like this:
- local malware that does not have its own privileges exploits a vulnerability in the AI client to obtain the agent’s token or communication channels and then leverages its extended rights;
- an attacker who gains remote access to the AI agent account (through a compromised token or password) extracts and systematizes all the information accumulated by the agent;
- configuration errors (for example, an enabled Messages connector in the presence of Full Disk Access) expand the agent’s actual access perimeter without a conscious decision by the user.
For businesses, this means growing risks of:
- leakage of trade secrets and customers’ personal data via “smart assistants”;
- more complex compliance with data protection regulations, since the information concentration point (the AI agent) is poorly reflected in existing registers of systems and data flows;
- additional attack surface for local insiders and malware focused not on direct privilege escalation, but on “riding” already privileged applications.
Practical recommendations: what to do before Apple’s updates arrive
For macOS administrators and power users
- Audit Full Disk Access
- Open System Settings → Privacy & Security → Full Disk Access.
- Make a list of all applications with full access.
- Disable Full Disk Access for AI clients and other applications that do not absolutely need it.
- Minimize AI agent integrations
- In Muse and similar products, disable integrations with messengers, the calendar, and email if you can do without them.
- For Muse, separately check whether the Messages connector is disabled if you do not clearly understand why you need it (given that, according to Meta, it is an “opt-in” option; see the Meta CTO’s comment).
- Update vulnerable applications
- Make sure the ChatGPT for Mac app is updated to a version where CVE‑2026‑100754 is fixed (use the latest version from the official changelog as a reference point).
- Check for Muse updates for macOS, as Meta has already fixed the demonstrated vulnerability related to unauthorized token access.
- Context separation
- Consider using a separate macOS user account or a separate workstation for AI agents that require extended rights.
- Do not store on the same system as a privileged AI agent any data whose criticality clearly exceeds the value of the convenience provided by the agent.
For developers of AI clients for macOS
- Principle of least privilege
- Avoid requesting Full Disk Access if you can get by with granular permissions (folder selection dialogs, access only to “Documents,” etc.).
- If FDA is still needed (for example, for file indexing), clearly separate functions: the module with full access should not have more network capabilities than required.
- Transparency for the user
- Clearly explain in the interface which types of data will become available to the AI agent when Full Disk Access and additional connectors (mail, messages, calendars) are enabled.
- Implement separate toggles for each integration type rather than a single generic “full access” option.
- Protection of internal channels and tokens
- Store tokens and sensitive settings in macOS protected storage (for example, Keychain), not in configuration files accessible to all local processes.
- Minimize the use of undocumented internal settings and carefully check whether they can be modified by external processes.
The key conclusion: Full Disk Access combined with AI agents turns any such application into a high-risk point in the macOS ecosystem. Therefore, before Apple’s updated mechanisms are released, you should already review the list of programs with full disk access, disable excessive connectors (such as Messages integration in Muse), and update AI clients, including ChatGPT for Mac, to versions with fixed vulnerabilities.