Apple macOS Full Disk Access access-control tightening
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Apple is tightening Full Disk Access in macOS, requiring an explicit user action before apps can gain broad access to files, mail, messages, browsing history, and other private data. The mitigation reduces the risk that AI agents or other apps can quietly bypass privacy protections and read or write sensitive system content. Apple said the change is meant to make users clearly understand the risk before granting that level of access, and the rollout date is still unknown.
Related Happenings
OpenAI ChatGPT app for Mac unauthorized access vulnerability (CVE-2026-100754)
Vulnerability
H score1
First: 05.10.2026 13:38
Last: 05.10.2026 13:38
Sources 1
How related:
Wardle has also been acknowledged for reporting another vulnerability, tracked as CVE-2026-100754, impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.
About this happening:
CVE-2026-100754 exposed OpenAI's ChatGPT app for Mac to unauthorized takeover, putting stored chat logs and other app data at risk. The flaw could let an attacker ta...
OpenAI ChatGPT app for Mac unauthorized access vulnerability (CVE-2026-100754)
VulnerabilityHow related: Wardle has also been acknowledged for reporting another vulnerability, tracked as CVE-2026-100754, impacting OpenAI's ChatGPT app for Mac that could have been abused to take over the AI assistant and grant an attacker unauthorized access to chat logs and other data stored by the app.
About this happening: CVE-2026-100754 exposed OpenAI's ChatGPT app for Mac to unauthorized takeover, putting stored chat logs and other app data at risk. The flaw could let an attacker ta...
Apple security patch release for CVE-2026-86950
Security Patch Release
H score24
First: 28.09.2026 22:18
Last: 28.09.2026 22:18
Sources 1
About this happening:
Apple released security updates for older iOS, iPadOS, and macOS branches to fix CVE-2026-86950, a flaw that could expose devices to arbitrary code execution. The...
Apple security patch release for CVE-2026-86950
Security Patch ReleaseAbout this happening: Apple released security updates for older iOS, iPadOS, and macOS branches to fix CVE-2026-86950, a flaw that could expose devices to arbitrary code execution. The...
Apple CoreGraphics out-of-bounds write security flaw (CVE-2026-86950)
Vulnerability
H score21
First: 28.09.2026 22:18
Last: 28.09.2026 22:18
Sources 1
About this happening:
Apple released updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that could enable arbitrary code execution on older iOS, iPadOS, and macOS ve...
Apple CoreGraphics out-of-bounds write security flaw (CVE-2026-86950)
VulnerabilityAbout this happening: Apple released updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that could enable arbitrary code execution on older iOS, iPadOS, and macOS ve...
Meta Muse Mac hidden dictation endpoint security flaw
Vulnerability
H score37
First: 22.09.2026 09:33
Last: 22.09.2026 09:33
Sources 1
How related:
The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said.
About this happening:
Meta's Muse assistant for Mac has a now-patched flaw that let an unprivileged local process redirect dictation traffic, capture dictated audio and prompts, inject trus...
Meta Muse Mac hidden dictation endpoint security flaw
VulnerabilityHow related: The now-patched vulnerability "can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app," Wardle said.
About this happening: Meta's Muse assistant for Mac has a now-patched flaw that let an unprivileged local process redirect dictation traffic, capture dictated audio and prompts, inject trus...
MacOS Screen Sharing authentication bypass actively exploited (CVE-2026-65400)
Vulnerability
H score86
First: 14.08.2026 17:59
Last: 14.08.2026 17:59
Sources 1
About this happening:
CVE-2026-65400 in macOS Screen Sharing is being actively exploited on systems with TCP port 5900 exposed to the internet, allowing network attackers to bypass...
MacOS Screen Sharing authentication bypass actively exploited (CVE-2026-65400)
VulnerabilityAbout this happening: CVE-2026-65400 in macOS Screen Sharing is being actively exploited on systems with TCP port 5900 exposed to the internet, allowing network attackers to bypass...
Timeline
-
05.10.2026 13:38 2 articles · 2h ago
Apple plans explicit user approval for macOS Full Disk Access
Mitigation Patch UpdateApple plans to update macOS Full Disk Access so the permission is granted only after an explicit user action. The change is intended to reduce the risk that AI agents or other developers can expose private system data such as files, mail, messages, and browsing history, and Apple has not said when the revised controls will ship.
Show sources
- Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access — thehackernews.com — 05.10.2026 13:38
- Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access — thehackernews.com — 05.10.2026 13:38