Apple says it is changing macOS privacy settings to stop third-party developers from misusing them to read message histories. In its statement, some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems, including files, mail, messages, and browsing history, without users fully knowing and understanding. For communication apps, that can also affect the privacy of the people those users are talking to.

Apple goes on: as agents become more capable and more autonomous, the risks of this level of access will grow by a large amount. The company says it wants users to understand those risks before they grant the access, so they can decide about their own data and privacy. Apple did not name Meta, Muse, or any other app or developer.

[1]
A closed envelope on the left with an intact brown wax seal, and a wide empty field on the right.
The envelope stays closed and the seal is intact. The right side is empty. That is a permission that still looks shut, before any new control has been described. An illustration, not a system screenshot., AI-generated illustration, not a news photograph

The report places the change after a column from two weeks earlier. Columnist Jason Aten said Meta’s general-purpose agent Muse sent him an unsolicited notification about a thread between him and a coworker in Apple Messages. Aten said he never granted Muse permission to read his messages and had assumed they were off limits.

Meta CTO David Singleton’s reply was that Messages integration in the Muse Mac app is opt-in. Muse can read Messages content only if macOS Full Disk Access is granted and the Messages connector is enabled. macOS security researcher Patrick Wardle told Ars that, technically, Full Disk Access makes any non-root file readable, including browsing history, browser cookies, and chats. Ars asked Meta how Muse could be unable to read messages when other apps with the same privilege can. Meta’s only response was to quote Singleton again.

Ars writes that Apple’s statement at least appears to contradict Singleton. Singleton’s point was that Muse could not read Messages without the connector. Meta’s public relations did not answer questions sent on Friday. There are no known reports of other apps abusing this permission to read messages and browsing history. Ars also says Friday’s statement might not be about Muse, while noting that it arrived just after the public argument.

[1]

Apple’s announcement came 11 days after Wardle disclosed a Muse configuration that let any other app or code on the Mac take full control of the assistant, and from there reach the same resources Muse could reach. This piece does not describe how that configuration is triggered.

In the same period, Amazon blocked Muse from its platform. Amazon’s reason was that such apps should operate openly and respect a service provider’s decision about whether to participate.

For people using this kind of assistant, Ars’s advice is to set permissions carefully. Aten’s experience also suggests that care alone may not be enough. Apple says it will change the permission. The article does not describe the new control, the system version it will apply to, or a step users must take now.

[1]

要点

  • Apple will change Full Disk Access because it can expose files, mail, messages, and browsing history without users fully understanding.
  • Apple did not name Muse. Meta says the Messages connector must also be on. Apple’s statement does not match that.
  • The announcement came 11 days after Wardle disclosed a Muse configuration. The article does not describe the new control.