Apple Plans a More Deliberate Consent Step for Mac’s Full Disk Access
Apple plans explicit consent for Mac Full Disk Access amid AI agent risks, covering files, mail and messages; no timeline or macOS version yet.
Illustrative image generated with AI
Apple says granting system-wide access will require clearer user action
Apple plans to change how apps obtain Full Disk Access (FDA) on Mac, according to The Verge’s report, published October 2, 2026, at 8:08 PM UTC. Apple said users who choose to give an app this extensive permission will have to take “very explicit user action.”
The report says Apple’s plans concern both developers’ use of FDA and the process through which users grant it. TechCrunch had reported the planned change earlier, The Verge said. Apple did not specify a rollout date or describe how the new controls will work.
The cited report does not name an affected macOS version, an update, or a specific interface or enforcement mechanism. It also does not identify a CVE, formal severity rating, exploit, or confirmed compromise associated with the announcement. The story concerns the risks of broad access, rather than a disclosed software vulnerability.
FDA can expose multiple categories of personal data
On macOS, FDA lets an app access a user’s entire system. Apple has described the permission as largely bypassing the platform’s privacy controls. The permission was provided to let backup apps function properly on Mac.
Apple’s concern is that some developers use FDA in ways that could expose information without users fully understanding the access they have granted. The categories Apple identified include files, mail, messages, and browsing history.
That breadth is central to the planned change. FDA is not limited to a single file or one data category; it can give an app access across a user’s system. Apple’s stated aim is to make granting that level of access a more deliberate user decision.
The report does not describe a particular app’s use of FDA as a confirmed security incident. Nor does it establish that every app with the permission reads all available data.
Apple connects the risk to more capable AI agents
Apple said the risk associated with FDA will grow substantially as AI agents become more capable and autonomous. The report presents this as Apple’s rationale for changing the permission controls, not as evidence of a newly discovered macOS exploit.
The concern, as described by Apple, is that broad access may carry greater consequences when granted to software with increasing autonomy. The report does not explain how Apple will account for AI agents in the planned controls, or whether the change will alter FDA’s technical scope.
The announcement therefore leaves key implementation questions open. The cited report provides no timeline for deployment, and Apple had not immediately responded to The Verge’s request for comment.
Meta disputes the implication of a separate Muse report
The Verge also recounted a separate report by Inc.’s Jason Aten. Aten said Meta’s Muse AI appeared to know the contents of his messages, despite his account that he had not explicitly allowed access to them on his iPhone or Mac.
Meta spokesperson Andy Stone rejected the implication that Muse could access Messages without user consent, describing access as “entirely opt-in.” Stone said Muse can read Messages content only when a user enables both Full Disk Access and the Messages connector.
Those statements do not resolve what happened in Aten’s case. The cited reporting does not independently confirm that Muse accessed his Messages, explain a technical route by which it might have done so, or establish that a permission control failed. Meta’s description of the two required settings is the company’s account, not independent verification of Aten’s experience.
What the report tells users—and what remains unspecified
For users assessing Meta Muse, Stone’s explanation makes both permissions relevant: he said the app needs FDA and the Messages connector enabled to read Messages content. The report does not provide further user instructions or technical remediation details.
Apple’s planned control is not yet described in enough detail to assess how it will change the consent process. The cited report does not say when it will arrive or identify a specific macOS release. Until Apple provides those details, the announcement establishes the intended direction, but not the controls users will eventually encounter.
Sources
This article is an original reworking based on the sources below.




