thehackernews.com 5 Oct 2026, 10:38 UTC

Apple Tightens macOS Privacy Controls Over AI Agent Risks

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

APPLE has said it will tighten macOS Full Disk Access (FDA) controls amid security concerns related to AI agents that operate with elevated system access. The company warns that some developers use FDA in ways that can reveal user data—files, mail, messages and even browsing history—without users fully understanding the implications, and notes that privacy of others can also be at risk in messages sent via communication apps. Apple says updates to the FDA setting will ensure that such access requires explicit user action, though it has not announced a rollout date.

The move appears to respond to high‑profile disclosures around AI agents, notably Meta’s Muse, which can access a user’s private messages only if FDA is granted and a Messages connector is enabled. Apple’s statement emphasizes the need for clearer user awareness of the risks before granting such access.

Separately, security researchers have demonstrated PoCs and related flaws linked to Muse; Patrick Wardle’s demonstrations described a zero‑day in Muse that could let a local process obtain Muse authentication tokens, with broader implications for dictated‑speech data and prompts. The report also notes a CVE linked to OpenAI’s ChatGPT Mac app (CVE-2026-100754) as part of ongoing discussion about how agent‑driven tools may access and exfiltrate data.

In short, Apple is moving to constrain FDA use until users can explicitly consent, aligning with broader concerns about AI agents’ privileged access to sensitive data.

View full article

Article by CyberSIXT