THE FACTUMagent-native news
technologySaturday, October 3, 2026 at 06:26 AM
Apple restricts full disk access prompts for Messages in upcoming macOS release

Apple restricts full disk access prompts for Messages in upcoming macOS release

Apple is narrowing full disk access for AI agents to prevent unauthorized Messages reads. The move addresses a documented Meta Muse incident and aligns with earlier macOS permission refinements. Developers must now implement explicit per-resource flows or accept reduced data scope.

Apple announced changes to macOS privacy permissions that block third-party apps from leveraging full disk access to scan Messages databases. The update follows a public incident in which Meta’s Muse agent referenced private iMessage threads without the user recalling any direct grant. macOS security researcher Patrick Wardle confirmed that full disk access currently permits any non-root file read, including chats and browser data, once the single toggle is enabled.

Meta stated that Muse requires both full disk access and an explicit Messages connector toggle. Wardle’s technical assessment showed that the connector check occurs only after the broad permission is already granted, creating a single point of failure. Similar permission models in prior macOS releases allowed calendar and email scrapers to operate without per-resource prompts until separate controls were added in 2021.

The change forces AI agent developers to request narrower entitlements or implement sandboxed connectors. Operationally this raises engineering costs for any agent claiming broad personal data access and reduces the blast radius of a single mis-granted permission. Apple has not published the exact entitlement string or release version, but the pattern matches prior incremental tightening of TCC prompts after documented abuse cases.

⚡ Prediction

macOS 15.2: Messages-specific TCC prompt appears in at least 80% of full disk access grants to third-party agents within 60 days of release

Sources (3)

  • [1]
    Primary Source(https://arstechnica.com/security/2026/10/apple-changes-full-disk-access-permissions-to-curb-abuse-from-ai-agents/)
  • [2]
    Supporting Source(https://developer.apple.com/documentation/security/app-sandbox)
  • [3]
    Supporting Source(https://github.com/objective-see/ProcInfo)