Skip to content
Apple changes full

Apple changes full

Arstechnica •Dan Goodin • October 2, 2026

Now, Apple is setting the record straight. In explaining why it was going to make changes to the FDA permission setting, the company wrote:

Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

The statement went on:

As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions their own data and privacy.

As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions their own data and privacy.

Apple didn’t name Meta, Muse, or any other app or developer by name. Even though there are no known reports of other apps abusing FDA to read messages and browsing history, it’s certainly possible Friday’s statement wasn’t referring to the Muse incident. Then again, the timing of the announcement—coming on the heels of a major social media uproar—makes the possibility likely. And at a minimum, Apple’s statements seem to contradict Singleton’s denial that it’s not possible for Muse to read Messages content without the connector enabled. Meta PR didn’t respond to questions sent Friday.

Apple’s announcement came 11 days after Wardle disclosed a Muse configuration that allowed any app or code running on a Mac—including commands injected through the increasingly effective ClickFix attacks—to take full control of the AI assistant . From there, the attacker could access the same resources Muse could. It also comes after Amazon blocked Muse from its platform because, Amazon said, all such apps “should operate openly and respect service provider decisions whether or not to participate.”

Taken together, the events suggest that Muse may not be worthy of the extraordinary access it must have to work as billed by Meta. People who use the assistant should configure permissions carefully, though as Aten’s experience suggests, that precaution only goes so far.

Extracted Entities

Malware (1)

Platforms (1)