Advisory
Published 2026-10-02
Verified 2026-10-03

Apple macOS Full Disk Access (2 Oct): extra explicit-consent controls coming — framed around AI-agent risk

Apple Developer News (2 October 2026; id=p6zjojqw) says macOS Full Disk Access (FDA) — the TCC privilege that largely sidesteps per-app privacy controls so backup apps can work — will gain additional controls so users who truly want to grant that extraordinary access can do so only with very explicit user action. Apple cites developers using FDA in ways that expose files, Mail, Messages and browsing history without users’ full understanding, and notes communication apps can also compromise the privacy of people users message. Framing: as AI agents become more capable and autonomous, FDA risk grows substantially; Apple commits to clearer risk disclosure before grant. No rollout date or OS version named in the notice. Context wires (Ars Technica / TechCrunch / MacRumors 2 Oct) link the move to debate over Meta Muse and other desktop AI agents that optionally request FDA plus in-app connectors. Not a CVE. Primary: Apple Developer News; wires: Ars / TechCrunch 2 Oct.

Product
macOS — Full Disk Access (TCC / Privacy & Security)
Versions
n/a — policy/control change announced 2 Oct 2026; implementation timing and macOS train not stated in Apple notice
Exploited in Australia?
unknown
Patch to
Mac admins / users: audit which apps hold Full Disk Access before granting to AI agents or chat clients; prefer least privilege; watch for Apple’s forthcoming explicit-consent UI in a future macOS update. MDM fleets: inventory FDA entitlements and treat agent apps as high-risk grants. Not an emergency CVE patch.

Primary: Apple Developer News — Updates to Full Disk Access in macOS (2 Oct 2026) · Vendor: Apple Developer (company primary) · Ars Technica — Apple changes full-disk access permissions to curb AI-agent abuse (2 Oct 2026)

ai identity