// 9TO5MAC — MOBILE & WEB
Full Disk Access on Mac: Here’s what Apple must, and must not, do
We’ve seen a number of examples of why giving Meta’s Muse app full disk access to your Mac is a very bad idea, and yet another major privacy issue has recently been discovered. It’s now been found that Muse analyzes your communication with everyone in your life on an hourly basis.
Apple is rightly concerned about the development, and in a blog post says that it will be introducing additional controls around the Full Disk Access feature that’s been enabling the problems …
Meta recently launched its Muse Personal AI Agent for iPhone and Mac. Despite the obvious inadvisability of giving a Meta app unfettered access to everything on your Apple devices, the app quickly jumped to the top of the App Store.
Predictably, it wasn’t long before things started to go horribly wrong. Things haven’t gotten any better since then, with Wired reporting that security researcher Karan Joshi found Meta had instructed Muse to extract all of the information needed to construct a complete map of all of your relationships.
One of Muse’s instructions appears to be the ability for it to create “a page for every person in the user’s life.” This hourly process involves compiling data on family, partners, friends, colleagues, “collaborators,” and people you “follow,” the instructions say […]
“Where they live, what they do, the threads that recur (the apartment move, the shared savings goal),” the instructions say. They add, too, that the model could record the “dates that matter,” such as birthdays or anniversaries. A person’s history could include backstory like “the trip in March, the argument that got resolved, the milestone last week.”
You would think a permission prompt to give an app “full disk access” to your Mac would be self-explanatory, but it appears not. Even tech-savvy people have been granting this access-all-areas pass to their machines without appreciating just how dangerous a step it is.
Apple says the feature was intended for backup apps, but developers are now using it for many more things, including AI agents. The company has said it intends to “introduce additional controls” to ensure users fully understand what they are doing if they grant this permission.
Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action.
Apple says it is “critical” to take this step, and I fully agree. When it’s become clear that the existing permission request doesn’t fully communicate the gravity of granting it, it’s essential that Apple ensure users genuinely understand what it is they are allowing.