Apple will change macOS full-disk access permissions after an incident in which Meta's AI agent Muse referenced a private Apple Messages thread without clear user consent. The move follows a public dispute over whether Muse needed an opt-in Messages connector or could read chats through system-level access alone. For business, the case shows how quickly broad agent permissions turn into privacy and liability exposure.

Apple to Restrict Full-Disk Access After Muse Read Messages

How the Muse messages incident unfolded

Tech columnist Jason Aten said Muse sent him an unsolicited notification referencing a thread with a co-worker over Apple Messages. He said he never granted permission to read messages and had assumed they were off limits. The report triggered wide discussion on social media, with users comparing AI assistants connected to calendars, email, messages and shopping accounts to power tools that cause damage when handled carelessly.

Meta CTO David Singleton responded that the Messages integration in the Muse Mac app is opt in. According to him, Muse can read Messages content only when macOS system-level Full Disk Access is granted and the Messages connector is enabled. The implication was that Aten must have enabled both settings, placing responsibility on the user rather than Meta. Meta public relations later repeated the same statement without further explanation.

Security researcher Patrick Wardle challenged that account on technical grounds. He noted that with full-disk access, any non-root file becomes readable, including browsing history, browser cookies and chats. Apple then stated that some developers use Full Disk Access in ways that expose files, mail, messages and browsing history without full user understanding. The company added that such access can also compromise the privacy of other people involved in user communications.

What tighter disk access means for companies

For companies testing AI agents on employee Macs, the immediate consequence is stricter consent around system-level permissions. Apple said risks will grow substantially as agents become more capable and autonomous, and users must understand them before granting access. Small teams may feel the change as extra setup steps, while large organizations gain a clearer basis for limiting which assistants receive full-disk rights on managed devices.

At the same time, broad permissions remain difficult to evaluate during procurement. The Muse case leaves open how much data an agent can reach once full-disk access is granted, regardless of individual connectors. Amazon has already blocked Muse from its platform, saying such apps should operate openly and respect service provider decisions about participation. Buyers should ask vendors exactly which files, accounts and histories an agent needs, how connectors are separated, and what remains accessible when a connector is off.

The marker to watch is how Apple implements the revised Full Disk Access prompt and whether Meta adjusts Muse permissions or documentation in response. A separate disclosure 11 days earlier showed that any app or code on a Mac, including commands injected through ClickFix attacks, could take control of the assistant and its resources. If vendors narrow requested access and clarify connector behavior, agents will be easier to approve for work use.