Home / Technology

Apple tightens access rights for Mac system

Apple has pushed out an update to macOS access rights, meant to fix the rampant abuse of AI privacy that is currently rampant, and deal with the vulnerability of AI tools crossing their boundaries to access private data.

Apple tightens access rights for Mac system

The AI privacy controversy exploded and Apple made an emergency change to its rules.

A user privacy incident exposed security loopholes in AI applications on the Mac platform. The AI assistants, originally intended to enhance efficiency, turned into tools for privacy snooping. People gradually realized that after obtaining system permissions, AI tools pose a significant risk of privacy leakage. Various third-party AI applications, relying on system permissions, freely collected users' private data without clear permission boundaries and risk warnings.
Jason Aten, a columnist, accidentally discovered that Meta's AI assistant Muse actively pushed his own and his colleagues' private chat contents. This conversation came from the Messages app provided by Apple, and he had never manually authorized the AI to read the messages. After this incident was exposed, many users reported that after installing various AI assistants, their privacy information was mysteriously read and accessed. This public opinion controversy directly prompted Apple to initiate a system permission rectification.

Meta and users are engaged in a power struggle over permissions.

Meta was quick to react, and took a very hard line. "We will never access private user messages with Muse," Meta's chief technology officer, David Singley, said in a public defense of the product. The message reading function can be enabled only if two rigid conditions are met. The user has to manually provide full access to the macOS system first. Second, you need to enable the message connector in Muse. According to Meta, the privacy reading issue was entirely caused by the user's own authorized operation and had nothing to do with product design flaws.
However, professional security experts directly refuted this statement. macOS security experts said that as long as full access is obtained, the application can read almost all non-encrypted data on the device. Chat records, browsing traces, all can be freely obtained, and there are no secondary authorization restrictions. Even if the user has not separately enabled the AI's message permission, as long as full access is granted, the AI tool can still bypass the restrictions and capture private content.

Apple takes action, reconfiguring the security system for AI permissions.

Apple released an official announcement on Friday, announcing the adjustment of the full access permission rules for macOS. The announcement did not specifically mention Meta and Muse, but the rectification measures were highly targeted, precisely addressing the current chaos of AI abusing access permissions. Apple clearly stated that many developers are currently using the full access function in violation of regulations. Most users are unaware of the actual risks of this permission. After granting it, third-party applications can freely read emails, messages, browsing history, local files and other core private data. This not only infringes on user privacy but also poses a threat to the information security of the chat partners.

Multiple security risks have been exposed.

The Muse privacy leak incident is just the tip of the iceberg when it comes to AI security issues. Security experts later disclosed even more serious vulnerabilities. The Muse on the Mac platform has serious configuration flaws. Criminals can inject code through ClickFix attacks and completely take over all the permissions of the AI assistant.
Once the attack takes effect, hackers can use the permissions of Muse to read all the user's private data and control all the functions of the device. Such vulnerabilities are almost impossible for ordinary users to detect and are extremely covert and harmful. Not only in the Apple ecosystem, but also on other platforms, Muse has encountered repeated setbacks. Amazon has banned the operation of Muse on its own platform. The consecutive bans on multiple platforms confirm that the abuse of permissions by this AI tool does indeed exist.

The lack of industry rules leads to chaos in AI permissions.

Most AI assistants on the market rely on high system permissions to provide services in all scenarios. However, the industry has never established clear permission classification standards or corresponding risk control mechanisms. AI tools have the characteristics of autonomous learning and automatic scanning. Once granted the same level of permissions, they will indiscriminately traverse all user data.
Many AI companies deliberately downplay the risks of authorization and only promote the efficient and convenient functions, without informing users of the privacy risks after authorization. Ordinary users, in order to use all the functions, often grant authorization with one click, inadvertently handing over all data permissions, thus creating a potential leakage hazard.

Trending / Guess you like

The OECD's new steel regulations have taken effect, leading to an escalation of trade barriers At the end of the month, the price of crude oil dropped, but the monthly upward trend remained unchanged UK diesel spot price hits new high, energy futures show signs of strengthening The United States has lowered vehicle fuel efficiency standards The delayed harvest of soybeans in the United States has led to a rush to purchase The significant reduction in rice production in India has impacted supply US Treasury yields exceed 5%, US stock futures experience a pullback The nationwide strike in France disrupted energy supply