Apple warns AI apps could be secretly reading your Mac files

Apple warns AI apps are abusing Mac disk access permissions

Apple is tightening controls around Full Disk Access as increasingly capable AI apps raise new privacy concerns on Mac | ©Image Credit: Unsplash / Emiliano Vittoriosi
Apple is tightening controls around Full Disk Access as increasingly capable AI apps raise new privacy concerns on Mac | ©Image Credit: Unsplash / Emiliano Vittoriosi Apple is tightening controls around Full Disk Access as increasingly capable AI apps raise new privacy concerns on Mac | ©Image Credit: Unsplash / Emiliano Vittoriosi

Your Mac has a permission that can basically unlock the filing cabinet. It turns out some AI apps may be using it in ways that could expose far more personal data than users realize. And Apple is warning against this.

The company says it plans to introduce additional controls for Full Disk Access in macOS as AI agents become more capable and autonomous. According to the company, users will have to take explicit action before granting apps this level of access. There is, however, no information on when the new controls will arrive or exactly what they will look like.

Full Disk Access is pretty much the VIP pass

macOS already has APIs designed to keep apps away from sensitive user data unless they have permission to access it. Full Disk Access is the exception that can open a much bigger door.

The permission exists for legitimate reasons. Backup apps, security tools, and other software sometimes need broad access to files and system data to actually do their jobs. The problem is what happens when an app, particularly an increasingly autonomous AI app, gets that same level of access.

Apple says some developers are using Full Disk Access in ways that could expose files, emails, messages, and browsing history without users fully understanding what they’ve agreed to. And if an app can access your messages or emails, it may also be able to see information belonging to other people you communicate with.

AI agents are making it harder

The timing here is interesting because AI models are becoming more like agents that can actually interact with computers, websites and files. That comes with its own set of security problems.

In July, OpenAI said its models breached Hugging Face during a cybersecurity evaluation after exploiting a vulnerability to gain internet access. Anthropic later disclosed that Claude models accessed the systems of three organizations during security tests through an unintended internet connection. Both companies said those tests were conducted without some of the safeguards used in their deployed products.

Then, in September, Australian authorities said an OpenAI agent had accessed public and non-public files on the country’s Medicare statistics reporting portal and written files to an internal server. No personal information was believed to have been accessed at the time.

None of those incidents necessarily means your AI assistant is secretly rummaging through your Mac right now. But it helps to understand the risks before granting Full Disk Access.

Source: Help Net Security, Apple Insider