Apple modifies macOS permissions to restrict AI agent access

Technology, AI44 minutes ago

Apple has announced changes to its macOS privacy settings designed to prevent third-party developers from misusing full-disk access permissions. The update aims to stop applications from accessing sensitive user data, including message histories, without clear consent. This move follows a significant controversy regarding the capabilities of artificial intelligence agents and their interaction with personal data on Apple devices.

The decision comes two weeks after tech columnist Jason Aten reported that Meta’s general-purpose AI agent, Muse, sent him an unsolicited notification referencing a private thread between him and a co-worker. Aten stated that he had not granted Muse permission to read his messages and believed such data was inaccessible to the application. The incident sparked widespread discussion on social media, with many users comparing AI assistants with broad access to dangerous power tools. Critics argued that while such tools are useful, they pose a risk of causing significant harm if not handled with extreme care.

Meta CTO David Singleton responded to the allegations by asserting that accessing Apple Messages requires two specific user actions. He explained that a user must manually grant full-disk access, a system-level permission, and enable a specific Messages connector setting within the Muse application. Singleton emphasised that the integration is strictly opt-in, implying that the columnist had enabled both settings and therefore bore responsibility for the data exposure. He maintained that Muse could only read message content if these specific permissions were active.

However, macOS security expert Patrick Wardle challenged this explanation. Wardle noted that from a technical perspective, full-disk access allows any non-root file to be readable, including browsing history, cookies, and chats. He questioned how Muse could be restricted from reading messages when other applications with the same privilege could access them. Meta’s public relations team did not provide a new technical explanation, instead repeating Singleton’s statement that the integration is opt-in and requires both full-disk access and the enabled connector.

Apple’s statement addressed the broader issue of developers using full-disk access in ways that could put users at risk. The company noted that this permission can expose files, mail, messages, and browsing history without the user’s full understanding. Apple highlighted that for communication apps, this can compromise the privacy of the people users are communicating with. The company stated that as AI agents become more autonomous, the risks associated with this level of access will grow substantially. Apple committed to ensuring users clearly understand these risks before granting access, allowing them to make informed decisions about their data.

The announcement did not name Meta, Muse, or any other specific developer. However, the timing of the statement, following a major public uproar, suggests a direct link to the recent incident. Apple’s position appears to contradict Singleton’s denial that it is impossible for Muse to read messages without the connector enabled. Meta did not respond to further questions sent on Friday.

This development also follows a disclosure by Wardle of a Muse configuration that allowed any app or code running on a Mac to take full control of the AI assistant. This vulnerability could potentially be exploited through injected commands to access the same resources available to Muse. Additionally, Amazon recently blocked Muse from its platform, stating that such applications should operate openly and respect service provider decisions. These events collectively suggest that the extraordinary access required by such AI agents may pose significant security and privacy challenges for users.

Post Disclaimer

The following content has been published by Stockmark.IT. All information utilised in the creation of this communication has been gathered from publicly available sources that we consider reliable. Nevertheless, we cannot guarantee the accuracy or completeness of this communication.

This communication is intended solely for informational purposes and should not be construed as an offer, recommendation, solicitation, inducement, or invitation by or on behalf of the Company or any affiliates to engage in any investment activities. The opinions and views expressed by the authors are their own and do not necessarily reflect those of the Company, its affiliates, or any other third party.

The services and products mentioned in this communication may not be suitable for all recipients, by continuing to read this website and its content you agree to the terms of this disclaimer.

Our Socials

Recent Posts

Stockmark.1T logo with computer monitor icon from Stockmark.it
Loading Next Post...
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...