Updates to Full Disk Access in macOS
- ID: 14db6845
- 原文链接: https://developer.apple.com/news/?id=p6zjojqw
- 作者: Apple
- 日期: 2026-10-02
- 分类: agents
- 来源类型: news
- 标签: apple、macos、full-disk-access、ai-agents、permissions、privacy
- 质量评分: 4/5
- 抓取时间: 2026-10-03 (daily-intake-evening, opencli web fetch)
中文导读
Apple 2026-10-02 发布开发者公告,宣布收紧 macOS Full Disk Access(FDA)。要点:FDA 基本绕过隐私控制体系,原本主要为让备份类 App 正常工作;一些开发者正在以「置用户于风险」的方式使用 FDA,暴露系统上的全部内容——文件、邮件、信息、甚至浏览历史——而用户并未充分知情和理解;对通讯类 App,还会连带损害用户通讯对象的隐私。后续 Apple 将引入额外控件:确需授予这一「特别权限级别」的 App,只能通过非常明确的用户动作(very explicit user action)完成授权。Apple 把 AI agents 点名为风险放大的原因:「随着 AI agents 变得越来越有能力、越来越自主,这一权限级别相关的风险将大幅增长」。公告未给出具体 macOS 版本或生效日期。
为什么值得关注
平台方首次把 agent 自主性写进权限收紧理由:本地 agent 的默认权限设计将不能再假设「用户点头 = 全盘可读」。
English Summary
Apple's October 2, 2026 developer announcement tightens macOS Full Disk Access: FDA largely sidesteps the privacy-control stack (it exists mainly so backup apps function), and some developers use it in ways that put users at risk by exposing everything on their systems - files, mail, messages, even browsing history - without users' full knowledge, with communication apps also compromising the privacy of the people users talk to. Going forward, Apple will introduce additional controls so that only very explicit user action can grant this extraordinary access level. Critically for the field, Apple names AI agents as the reason risks 'will grow substantially' as agents become increasingly capable and autonomous. No specific macOS version or effective date was given.
原文全文
We give developers powerful APIs to build incredible capabilities into their apps for Apple products, backed by a set of controls designed to protect users' private data. Full Disk Access largely sidesteps these controls in order to allow backup apps to function properly on the Mac. Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users' full knowledge and understanding. For communication apps, this can also compromise the privacy of the people users are communicating with.
Going forward, we will introduce additional controls to ensure that users who genuinely wish to grant an app this extraordinary level of access can only do so with very explicit user action. Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy.
Notes
- Full text fetched 2026-10-03 via
opencli web read --url https://developer.apple.com/news/?id=p6zjojqw --download-images false -f mdduring daily-intake-evening (complete announcement, ~1.4 KB, stored above verbatim). - Context from same-day vault research note: 调研/2026-10-03-调研-macOS-Full-Disk-Access-本地Agent权限.md (TechCrunch/The Verge coverage places this after the Meta Muse controversy; Claude Code 2.1.288's dangerous-rm fix shows local-command authorization tightening in parallel).
- 中文导读 block is the entry's summary_zh (verbatim); 为什么值得关注 is the entry's one_liner; no claims beyond the fetched source text were added.