{
  "id": 12356974,
  "title": "Apple Just Admitted the Permission Model Was Never Built for Agents That Read Everything",
  "url": "https://urgent.news/2026/10/06/apple-just-admitted-the-permission-model-was-never-built-for-agents",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T10:37:38.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/coridev/apple-just-admitted-the-permission-model-was-never-built-for-agents-that-read-everything-3afp"
  },
  "original_language": "en",
  "account": "Apple has acknowledged that its permission model has never been designed for agents that can read everything, according to recent updates. Full Disk Access on macOS, which has been a binary switch for a decade, allowing apps to either see the entire filesystem or not, has been quietly broken. This revelation highlights a long-standing issue with overly broad OS permissions, a known weak point since the early days of mobile app sandboxing. The difference now is the actor requesting access: a human-driven app has a predictable blast radius, but an AI agent with the same grant can read sensitive information like Messages, browser session tokens, and chat logs, deciding on its own what is relevant to its task. This is not a new vulnerability class, but an old one with a new badge. The issue lies in the assumption of a fixed program with fixed behavior, which agents break by design. Apple's response to this issue is more about security 101, tightening Full Disk Access due to agents reading everything they were given access to, rather than innovating. The industry's permission scoping has lagged behind the capabilities of these agents, as seen with Meta's Muse and the ChatGPT Mac app, which did not exploit the access granted in a clever or adversarial manner. The real story is that the way these apps use granted access now means accessing private chat history and browser sessions for context, an industry-wide problem, not just an Apple-specific one. This situation benefits Apple by looking proactive and user-protective with a modest permissions tweak, and AI vendors by pointing at Apple's OS vendor fixing the root cause instead of addressing their own agents' broad access request patterns. Developers are warned about scope creep in permissions requests, and security teams are reminded that threat models for installed applications and autonomous agents with filesystem access cannot be the same. Other OS vendors may follow Apple's move, or stay an Apple-only move while others wait for an incident to force changes. The question remains why agents default to requesting broad access instead of scoped, task-specific permissions, and if it's the OS vendors' or AI vendors' job to enforce this from the start.",
  "summary": "Full Disk Access on macOS has been a binary switch for a decade: an app either gets to see your whole filesystem or it doesn't. That design assumption just quietly broke, and Apple's response tells you more than the incidents that caused it. Context This isn't a new vulnerability class. It's an old one wearing a new badge. Overly broad OS permissions have been a known weak point since the…",
  "key_points": [
    "Apple acknowledges permission model never built for full access agents",
    "Full Disk Access on macOS broken, allowing apps to read entire filesystem",
    "AI agents can access sensitive data, prompting Apple to tighten security"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}