Apple Is Rewriting macOS Permissions After Meta’s Muse Was Accused of Reading Private Messages

A MacBook glowing with pink and blue neon light on a dark desk

Apple said Friday it will change macOS to make it unmistakable when AI agents ask for access to everything on your Mac — a direct response to complaints that Meta’s Muse agent read users’ private messages. “As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially,” Apple wrote in a post announcing the change, Reuters reports.

The sandbox gap nobody noticed

Here is the technical detail that makes this story bigger than one agent. On iPhone and iPad, no single app can read data inside another app by default — a technique called sandboxing. Your notes app cannot see your messages, period. But the Mac is more flexible: it offers a “Full Disk Access” permission that lets apps like cloud backup services read everything on the machine, with the user’s permission.

That permission was designed for backup utilities. AI agents — which need broad access to do useful things like canceling subscriptions — walked straight through the same door. Apple said Friday that “some developers were using the Full Disk Access feature in ways that could put users at risk,” and promised “additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.”

He said, she said

The trigger was an accusation by Inc. magazine technology columnist Jason Aten, who said Meta’s Muse read his private messages on his Mac — and that he had not enabled Full Disk Access. When he asked the AI how it happened, it told him it was syncing his “device notifications,” meaning, Aten believes, that Muse was passing along the text of his incoming banner notifications to the agent.

Meta pushed back hard. Spokesperson Andy Stone said Muse’s access to Apple’s Messages app is strictly opt-in: “You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can’t read your Messages unless you do this. And it can be revoked at any time.” Meta’s David Singleton countered that reading messages requires three separate permission steps plus macOS protections that “can’t be circumvented even if the Muse application had a bug” — and said the AI’s notification-syncing explanation was simply wrong, TechCrunch reports.

To be clear: Aten’s claim is unverified, and Meta flatly denies it. But Apple clearly decided the dispute itself was the signal — regardless of who is right about Muse, the permission model let the question arise at all.

Check your own Mac in 30 seconds

Whatever you believe about Muse, audit who holds Full Disk Access on your Mac right now. Open System Settings → Privacy & Security → Full Disk Access and look at the list.

Keep the backup utilities and security tools you deliberately installed. Question everything else, especially anything with “AI,” “agent,” or “assistant” in the name that you granted access to during a hurried onboarding flow. Revoking is instant, and any legitimate app will simply ask again if it needs the permission back.

Why this matters: the agentic permission crisis

The commodity rewrites treat this as a one-day spat between Apple and Meta. The real story is structural: the entire agentic-AI industry has a permission problem it has not solved. An agent that cannot see your data is useless; an agent that can see all of it is a liability. Every AI agent company is currently threading that needle with consent dialogs most users click through without reading.

Apple’s move is the first time a platform owner has said the quiet part out loud — that Full Disk Access was never designed for autonomous agents, and that “very explicit user action” will now be required. Expect every other platform to follow. The age of the agent quietly holding the keys to your entire machine is ending; what replaces it will be slower, more annoying, and considerably safer.

Meanwhile in Tech News: Synopsys, OpenAI, and AWS’s chip-design deals.

Meanwhile in Tech News: HPE and Vultr’s $1.2 billion AI order built on AMD Helios.

Written by
Nathan covers breaking tech news — Big Tech earnings, antitrust battles, cybersecurity incidents, and the stories moving the industry day to day.