Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

Citing growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls.

Data protection

Apple has announced tightened Full Disk Access controls in macOS in light of the risks posed by continuously evolving AI agents.

Apple introduced Full Disk Access in macOS Mojave (10.14) to provide users with control over applications’ access to the entire system. The feature can be toggled on or off from Apple menu > System Settings > Privacy & Security.

By default, macOS restricts applications from accessing system-protected areas and sensitive user data. Granting an application Full Disk Access waives these protections, allowing that software to read or modify private files, including a user’s mail, messages, and browsing history.

Improperly managed Full Disk Access permissions may result in malicious applications gaining access to sensitive information, and Apple is now planning tightened controls around it, as AI agents and modern applications are increasingly requesting Full Disk Access.

According to Apple, some applications are using Full Disk Access in ways that could put users at risk by exposing their files, mail, messages, and browsing history without users’ full knowledge and understanding.

“For communication apps, this can also compromise the privacy of the people users are communicating with,” Apple said on Friday.

Advertisement. Scroll to continue reading.

Citing risks posed by more potent AI agents, the company will introduce additional controls ensuring that applications are provided with this level of access only with the users’ explicit consent.

“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy,” Apple said.

The company did not specify when the additional controls will be rolled out, nor did it say what exactly determined it to introduce them.

Two weeks ago, tech journalist Jason Aten revealed that Meta’s personal assistant Muse accessed his private iMessages even though he believed Full Disk Access was disabled. Meta executives disputed the claim, maintaining that both Full Disk Access and a Messages connector must be explicitly enabled.

Related: Social Engineering Detection Moves Into the Live Conversation

Related: Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Related: AI Agents Aimed SQL Injection at US and Canadian Government Sites

Related: Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.