Apple disclosed on Friday that it will modify the way macOS handles full‑disk access permissions in an effort to stop third‑party developers from exploiting the privilege to read users’ message histories. The move follows a public dispute that began when technology columnist Jason Aten claimed that Meta’s general‑purpose AI agent, Muse, accessed a private Apple Messages conversation without his authorization.
Background of the Muse incident
Two weeks after Aten’s report, the story gained traction on social media, with many users echoing concerns that AI assistants granted access to calendars, emails, messages, and shopping accounts could become “power tools” capable of causing real harm if misused. Aten said he never gave Muse permission to read his messages and had assumed the app could not access them without explicit consent.
Meta’s chief technology officer, David Singleton, responded by emphasizing that Muse’s ability to read Apple Messages is “opt‑in.” According to Singleton, a user must manually enable two separate settings for Muse to access message content: the macOS system‑level Full Disk Access (FDA) permission and a specific Messages connector within the Muse application. He suggested that if both settings were enabled, the responsibility for any unauthorized reading lay with the user, not with Meta.
Security researcher Patrick Wardle, known for his work on macOS security, challenged Singleton’s explanation. Wardle argued that once an app receives full‑disk access, it can read any non‑root file on the system, including browsing history, cookies, and chat logs. He questioned why Muse would be unable to read Messages content when other applications with the same privilege can do so. Meta’s public‑relations response reiterated Singleton’s earlier statement without providing additional technical clarification.
Apple’s privacy setting overhaul
In reaction to the controversy, Apple announced it will change how full‑disk access permissions are granted and managed. While the company has not disclosed the exact technical details, the stated goal is to prevent third‑party apps, including AI agents, from abusing system‑level privileges to harvest private communications. Apple’s adjustment is intended to make the opt‑in process more transparent and to give users clearer control over which applications can read sensitive data stored on their Macs.
The timing of Apple’s announcement suggests a direct response to the Muse episode, highlighting the broader industry debate over the balance between AI functionality and user privacy. By tightening the full‑disk access framework, Apple aims to reinforce its reputation for safeguarding personal information on its platforms.
Industry observers note that the incident underscores the challenges of integrating AI assistants into operating systems that already grant powerful permissions to applications. As AI capabilities expand, the need for granular, enforceable privacy controls becomes increasingly critical. Apple’s forthcoming changes may set a precedent for other platform providers grappling with similar concerns.
For now, users of macOS are advised to review their Full Disk Access settings and ensure that only trusted applications have the ability to read files across the system. Apple’s updated privacy controls are expected to roll out in an upcoming macOS update, though the exact release schedule has not been specified.
Mitchell Landsberg is a Senior Technology Correspondent at News Raise. He covers consumer electronics, artificial intelligence, software developments, and digital privacy trends.




