Cyber Security News

Apple Tightens macOS Full Disk Access as AI Agents Become More Powerful

Apple plans to add stronger controls to Full Disk Access in macOS, warning that the powerful permission can expose a user’s most private data as AI agents become more capable. The company said the change will require users to take a far more deliberate action before granting an app this broad level of access.

Full Disk Access was built to help trusted Mac tools, mainly backup software, work around normal privacy limits when needed. However, the permission can let an app reach files across the Mac, along with data held by Mail, Messages, Safari, Home, Time Machine backups, and certain system settings.

Apple’s current guidance already treats the setting as a high-risk permission, requiring users to manually add an app through the Privacy & Security section of macOS settings.

Apple Tightens macOS Full Disk Access

Apple said some developers are using Full Disk Access in ways that may leave users unaware of how much information an app can see. The concern is not limited to documents stored on the device.

A granted app may be able to access email, private chats, browsing history, and other personal records that are normally protected by macOS controls. For communication tools, the privacy impact can also extend to other people involved in those conversations.

The growing use of AI agents makes this issue more serious. Unlike a normal app that performs one clear task, an AI agent may read information from several sources, process it, and take further actions based on what it finds.

Broad disk access could therefore give an agent visibility into a large amount of personal or business data. Apple said the risks will grow substantially as these tools become more capable and act with greater independence.

Apple has not yet shared the exact design, release date, or supported macOS versions for the additional controls. Still, its wording suggests the company wants to move beyond a simple permission toggle and make users clearly understand the scope of access before enabling it.

The change does not appear to remove Full Disk Access from legitimate backup, security, or recovery tools. Instead, it aims to make sure people consciously approve an exceptional permission rather than enabling it while rushing through an app setup process.

For Mac users, the immediate step is to review the existing list of apps with Full Disk Access. Open System Settings, select Privacy & Security, and then choose Full Disk Access.

Remove access for tools that are no longer used or that do not have a clear need to read data from across the system. This is particularly important for desktop AI assistants, browser extensions, system cleaners, and communication apps.

The move also follows wider concern about weaknesses around macOS Transparency, Consent, and Control protections. Cyber Security News recently reported on a macOS TCC bypass vulnerability and on the growing risks of AI agents carrying out ransomware activity.

Apple’s planned update shows that strong permission design is becoming a key security control as AI software gains deeper access to user devices.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

53 minutes ago

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

54 minutes ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

1 hour ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

2 hours ago

Top 10 Best SAST Tools in 2026 [Ranked & Scored]

The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…

2 hours ago

Top 10 Best Just-in-Time (JIT) Access Tools in 2026 [Ranked & Scored]

Credentials that always work are credentials worth stealing which is why mitigating how attackers exploit…

3 hours ago