Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple Just Admitted the Permission Model Was Never Built for Agents That Read Everything

Full Disk Access on macOS has been a binary switch for a decade: an app either gets to see your whole filesystem or it doesn't. That design assumption just quietly broke, and Apple's response tells you more than the incidents that caused it. Context This isn't a new vulnerability class. It's an old one wearing a new badge. Overly broad OS permissions have been a known weak point since the…

Apple has acknowledged that its permission model has never been designed for agents that can read everything, according to recent updates. Full Disk Access on macOS, which has been a binary switch for a decade, allowing apps to either see the entire filesystem or not, has been quietly broken. This revelation highlights a long-standing issue with overly broad OS permissions, a known weak point since the early days of mobile app sandboxing.

The difference now is the actor requesting access: a human-driven app has a predictable blast radius, but an AI agent with the same grant can read sensitive information like Messages, browser session tokens, and chat logs, deciding on its own what is relevant to its task. This is not a new vulnerability class, but an old one with a new badge.

The issue lies in the assumption of a fixed program with fixed behavior, which agents break by design. Apple's response to this issue is more about security 101, tightening Full Disk Access due to agents reading everything they were given access to, rather than innovating. The industry's permission scoping has lagged behind the capabilities of these agents, as seen with Meta's Muse and the ChatGPT Mac app, which did not exploit the access granted in a clever or adversarial manner.

The real story is that the way these apps use granted access now means accessing private chat history and browser sessions for context, an industry-wide problem, not just an Apple-specific one. This situation benefits Apple by looking proactive and user-protective with a modest permissions tweak, and AI vendors by pointing at Apple's OS vendor fixing the root cause instead of addressing their own agents' broad access request patterns.

Developers are warned about scope creep in permissions requests, and security teams are reminded that threat models for installed applications and autonomous agents with filesystem access cannot be the same. Other OS vendors may follow Apple's move, or stay an Apple-only move while others wait for an incident to force changes. The question remains why agents default to requesting broad access instead of scoped, task-specific permissions, and if it's the OS vendors' or AI vendors' job to enforce this from the start.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Laravel Route Caching: What Breaks It in Production

Laravel route caching is one of the standard deploy optimizations, and one of the few that can break a site without a single error in your logs: a new page that returns 404 only in production, a…

  • Route caching compiles routes into a single cached file for faster execution
  • Stale cache file causes 404 errors for new routes in production
  • Duplicate route names and closure routes can break cached routes

Your AI-built app works locally but breaks when you deploy it? Check these 6 things

You built an app with Cursor, Claude Code, Lovable or Bolt. On your laptop it's perfect. You deploy it, and you get a blank page, a 502 , or a login button that spins forever.

  • Frontend still calls localhost, causing connection failures in production
  • Frontend variables are static at build time, requiring server-side setup
  • Server listens on incorrect address/port; use 0.0.0.0 and PORT variable

Honam Chip Cluster Sparks Audit Clash

The Honam semiconductor cluster, the core of the ‘Three Mega Projects’ promoted by the Lee Jae-myung administration, was brought to the table at the parliamentary audit.

  • Honam semiconductor cluster part of South Korea's Three Mega Projects.
  • Government claims Samsung, SK hynix chose Honam region after evaluation.
  • Opposition argues companies never proposed specific region or investment plan.

More from Tuesday 6 October →