Safety & Security

Apple Tightens macOS Permissions to Block AI Agents From Reading Messages

Apple is restructuring macOS privacy settings after Meta's Muse agent surfaced private iMessage threads, closing the gap between user consent and expectation.

By Rebecca Stone3 min read

Updated

Why it matters

  • Apple announced Friday it is changing macOS privacy settings to stop third-party developers from misusing them to access message histories.
  • The change follows Jason Aten's report that Meta's Muse agent sent him an unsolicited notification referencing a private Apple Messages thread he never granted it access to.
  • Meta CTO David Singleton said Muse requires both manual full-disk access and an enabled Messages connector to read Apple Messages.

Apple said Friday it is changing macOS privacy settings to stop third-party app developers from misusing them to access users' message histories. The move targets a permission model that let Meta's new AI agent Muse read private Apple Messages threads without users realizing what they had authorized.

The announcement came two weeks after tech columnist Jason Aten reported that Muse sent him an unsolicited notification referencing a conversation between him and a co-worker over Apple Messages. Aten said he never granted Muse permission to read his messages and had assumed they were off-limits.

The incident struck a nerve. Social media filled last week with users who said they had similar experiences, and many drew the same conclusion: AI assistants given access to calendars, emails, messages, shopping accounts, and other personal resources are like a skill saw or any other power tool — potentially useful, but capable of real damage when not handled carefully.

A rebuttal that held up

Meta CTO David Singleton entered the debate with a rebuttal that appeared solid. For Muse to access Apple Messages, he explained, a user must manually grant it two separate privileges.

The first is full-disk access, a macOS system-level permission. The second is a Messages connector setting that must be enabled inside Muse itself.

That defense highlights the real problem Apple now faces. Technically, Muse users consented. They toggled a powerful macOS permission — full-disk access — that opens far more than messages, and then enabled a connector inside the app. But the consent was so far removed from the outcome, an AI agent surfacing private chat content in a notification, that users experienced it as a violation.

Why the stakes go beyond Meta

This is why Apple's change matters beyond one incident. The full-disk access permission predates the current wave of general-purpose AI agents. It was designed for backup tools, disk utilities, and antivirus software — applications where broad file access is the point and the blast radius of misuse is limited by what those apps do.

AI agents change that equation. An agent with full-disk access can read message databases, correlate that content with calendars, emails, and shopping accounts, and then act on what it finds — including sending notifications users never asked for. The permission's coarse, all-or-nothing design gives users no way to grant an agent access to, say, files, while keeping its hands off Messages.

Apple's intervention signals that the company sees system-level permission gates as its responsibility to maintain as AI agents proliferate on macOS. Singleton's rebuttal, whatever its technical merits, did not stop the reputational damage: users discovered a private conversation had been read by software they did not think could read it. Apple is now closing the gap between what users technically authorize and what they reasonably expect.

What changes

Under the changes announced Friday, Apple is restructuring how macOS privacy settings work so that third-party developers cannot misuse them to reach message histories. The company framed the move as a direct response to misuse of existing permissions rather than a general privacy overhaul.

For developers of AI agents, the message is blunt: broad system permissions will no longer double as a side door into iMessage data. For users, the change reduces the odds that an agent's access to one category of personal data silently expands to another.

The episode also marks an early test case for a problem the industry will face repeatedly: AI agents that act across many services need broad permissions, but broad permissions are exactly what turns a useful assistant into a privacy incident. Apple's fix suggests platform owners, not agent developers, will be the ones drawing the lines — and that expectation now sits with every OS maker whose permissions AI agents request.

Original: developer.apple.com

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

185 articles

Related articles

  1. Apple to Restrict macOS 'Full Disk Access' Over AI Agent Risks
  2. Meta Denies Muse Read Private Messages Without User Consent
  3. Zero-Day in Meta's Muse AI Assistant Undoes macOS Defenses
  4. Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover
  5. Meta Says Muse's Exposed Filesystem Is Intended Behavior

« Previous article