Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. The announcement follows a wave of public concern regarding how AI assistants handle sensitive user data when granted broad system permissions.
The Meta Muse Controversy
The policy shift comes two weeks after tech columnist Jason Aten reported that Meta’s new AI agent, Muse, sent him an unsolicited notification referencing a private thread from Apple Messages. Aten maintained he had never granted the assistant permission to read his chats.
Meta’s CTO, David Singleton, rebutted the claims, stating that Muse requires two manual privileges to access messages: system-level Full Disk Access (FDA) and a specific Messages connector within the app. However, macOS security expert Patrick Wardle challenged this defense, noting that from a technical standpoint, FDA allows an app to read almost any non-root file, including chat logs and browser cookies, regardless of in-app toggles.
Apple’s Response to AI Risks
While Apple did not explicitly name Meta or Muse, the company acknowledged that some developers are using FDA in ways that expose mail, messages, and browsing history without full user understanding. The tech giant emphasized that the rise of autonomous AI agents necessitates stricter oversight.
"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple stated.
The timing of Apple's intervention is notable, occurring shortly after Wardle disclosed a configuration flaw in Muse that could allow attackers to hijack the assistant. Furthermore, Amazon recently blocked Muse from its platform, citing the need for apps to respect service provider decisions regarding data participation.