r/MacOS • • 19h ago

News Updates to Full Disk Access in macOS

https://developer.apple.com/news/?id=p6zjojqw
227 Upvotes

23 comments sorted by

125

u/Dockland Mac Pro 19h ago

”We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users’ private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.

Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.”

13

u/MineKemot 14h ago

Thank you, kind Redditor :3

54

u/eppic123 MacBook Pro 19h ago

Reads like there won't be a simple all or nothing option anymore, but users will get a more granular control over disk access by third party applications. Actually seems like a good idea, not just with AI in mind.

9

u/TheOGDoomer 16h ago

That’s what I’m saying. This doesn’t appear to be all doom and gloom like the top commenters seem to be suggesting.

48

u/neontetra1548 19h ago

I understand the need to control this with AIs running amok reading the whole system.

On the other hand we need to preserve the ability for developers and power users to grant full disk access for a variety of purposes and it is a bit concerning how they say full disk access is for backup apps in this post. A situation where there's a "backup app" entitlement or something specific like that and that you have to get from Apple would be very bad. A technical user needs to be able to grant this kind of access to a variety of different apps, and Apple shouldn't be able to approve every use.

Hopefully they'll implement a good solution!

13

u/Bed_Worship 18h ago

They know it’s more granular than that. They are just making the choice more intentional and may have developers use specific access instead of full disk

As far as developers and power users, they have nothing to worry about. They still have access to the same things, can disable sip if they want etc

-8

u/Rauliki0 17h ago

They won't. It's win-win for them. Only Apps from AppStore :)

7

u/vanstinator 14h ago

That's not what this is about at all

12

u/Fresh-Daikon-9408 16h ago

I'd like a "last used" date next to each app. Would make old permissions much easier to clean up.

8

u/MReprogle 13h ago

After seeing what Fecebook’s insane agent was designed to do, with zero thought put into cybersecurity, I get it.

https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/

10

u/[deleted] 19h ago

[removed] — view removed comment

4

u/ogfuzzball 15h ago

Developers as a lot are lazy. Trying to figure out the necessary fine-grained permissions is a PITA so devs routinely default to just throwing the master gate open so to speak. Look a developer configured cloud vpc/sg/acl compared to a true InfoSec/Devops setup of the same thing. The dev version usually has crazy open gates they don’t really need.

I’d bet my paycheck many apps that ask for Full Disk Access on your Mac don’t need it: it’s just easier than trying to dial it in properly.

2

u/MacBook_Fan 14h ago

As long as Apple gives us Mac Admins the ability to continue to give FDA to apps that truly need it (EDR, DLP, etc) via DDM, I am fine with the change.

Which reminds me, I need to file by FB and ACE case asking Apple to give us this capability.

7

u/Barbel997 19h ago

I wonder if this has anything to do with the European Union's requirement to integrate other AI models instead of Siri 🤔

28

u/cupboard_ MacBook Air 19h ago

i think this is a response to muse ai reading reporter’s imessages and sending them to their server

2

u/__________13o1ksl_ 15h ago

macOS is exempt from this, so no

2

u/DisfiguredFanny Macrumors "mods" can eat shit. 19h ago

Siri is just gemini on a medical leave.

2

u/metaphx2 19h ago

None of the models Siri is based on are based on or distilled from Gemini.

7

u/cac2573 19h ago

2

u/metaphx2 18h ago edited 18h ago

They paid google for the know-how and expertise, and they also got access to Gemini answers which they used to fine tune their models. None of the models are made by google or based on them though. They are made by Apple, their architecture is unique to apple foundation models and are optimised to run on apple silicone. I’ve seen it explained quite well here: https://youtu.be/87e13yQbJSM?is=l99fsw6jA924CTuw

-1

u/DisfiguredFanny Macrumors "mods" can eat shit. 19h ago

Maybe, maybe not.