macOS Full Disk Access評測:蘋果收緊AI代理權限 | macOS Full Disk Access Review: Apple Curbs AI Agents
By Kit 小克 | AI Tool Observer | 2026-10-03
🇹🇼 macOS Full Disk Access評測:蘋果收緊AI代理權限
Full Disk Access(完整磁碟取用權限)這幾天成為Mac用戶最關心的詞。蘋果在2026年10月2日宣布,將收緊macOS的Full Disk Access控制機制,原因是近期多起AI代理(AI Agent)濫用這項權限存取使用者私人檔案、訊息與瀏覽紀錄的事件,包括Meta Muse被爆讀取私訊,以及ChatGPT Mac版出現可讓駭客竊取敏感資料的漏洞。對於天天開著Claude、ChatGPT、Cursor等AI代理工具跑任務的使用者來說,這次改動值得認真看一下。
發生了什麼事:兩起事件逼蘋果出手
這次收緊並非無的放矢。先是有記者在專欄中指出,Meta的AI代理應用Muse在未經明確同意的情況下讀取了他的私人訊息;接著Wired報導,ChatGPT的Mac桌面版存在一個漏洞,理論上能讓攻擊者透過該App取得使用者的敏感系統資料。蘋果在聲明中直接點名:「部分開發者使用Full Disk Access的方式,可能讓使用者在未完全理解的情況下暴露檔案、信件、訊息甚至瀏覽紀錄。」
Full Disk Access 到底給了AI代理多大的權力
Full Disk Access是macOS最高等級的檔案存取權限之一,一旦授予,App幾乎可以讀取整台Mac上的所有內容——不只是自己的沙盒資料夾,而是Mail、Messages、Safari歷史紀錄、其他App的儲存檔案都在範圍內。這正是許多AI代理工具會要求使用者開啟的權限,理由通常是「要幫你整理檔案」或「要讀取專案全部內容」。問題是,使用者往往在安裝精靈裡隨手點了「允許」,卻不清楚這代表什麼。
對正在用AI代理工具的你有什麼影響
蘋果這次沒有公布具體上線時間,只說會要求使用者透過「非常明確的操作」才能授予這項權限,等於是在授權流程上多加一道摩擦力。對開發者而言,這可能讓部分仰賴系統級存取的自動化代理工作流變得不那麼「無縫」;對一般使用者而言,這其實是好事——至少不會再有App悄悄拿到完整磁碟權限卻沒人察覺。
現在該做的事
- 打開「系統設定 > 隱私權與安全性 > Full Disk Access」,檢查清單上有哪些App擁有這項權限,尤其是AI相關工具
- 把用不到的AI代理App的Full Disk Access直接關掉,改用更小範圍的「檔案與資料夾」權限測試是否仍可運作
- 更新ChatGPT桌面版、Claude Desktop、Cursor等工具到最新版,修補已知漏洞
- 往後看到安裝精靈要求Full Disk Access時,多想一秒:這個功能真的需要讀取我的Mail和Messages嗎
AI代理工具確實好用,但「好用」跟「該給多少權限」是兩件事。蘋果這次收緊算是把選擇權還給使用者,剩下的就看每個App怎麼說服你按下「允許」。好不好用,試了才知道。
🇺🇸 macOS Full Disk Access Review: Apple Curbs AI Agents
If you have seen headlines about macOS Full Disk Access this week, here is the short version: Apple is tightening the permission that lets apps — including AI agents like ChatGPT desktop, Claude, and Cursor — read everything on your Mac. The change, announced October 2, 2026, comes after a journalist reported Meta Muse AI agent read their private messages without clear consent, and Wired flagged a ChatGPT Mac app flaw that could have let attackers pull sensitive data through the app.
What Triggered the Crackdown
Apple did not mince words in its statement: "Some developers are using Full Disk Access in ways that could put users at risk" — often without users fully understanding what they are granting. Full Disk Access is macOS top-tier file permission. Once granted, an app can read Mail, Messages, Safari history, and files belonging to other apps — not just its own sandbox. It is exactly the permission many AI agent tools ask for, usually framed as "so I can organize your files" or "so I can see your whole project."
Why This Matters If You Run AI Agents Daily
Apple has not given a firm rollout date, only that it will require "very explicit user action" before granting this level of access going forward. That is extra friction in the permission flow — annoying for developers who built workflows assuming seamless system access, but a reasonable guardrail for everyone else. The core issue is not that Full Disk Access is bad; it is that users have been clicking "Allow" during setup wizards without realizing the scope of what they just granted an autonomous agent.
What To Do Right Now
- Open System Settings > Privacy & Security > Full Disk Access and audit which apps already have it — especially AI tools
- Revoke Full Disk Access from any AI agent you do not actively need it for; try the narrower "Files and Folders" permission instead and see if it still works
- Update ChatGPT desktop, Claude Desktop, Cursor, and similar tools to patch known vulnerabilities
- Next time a setup wizard asks for Full Disk Access, pause for one second and ask: does this feature actually need to read my Mail and Messages?
AI agents are genuinely useful, but "useful" and "how much access it deserves" are two different questions. Apple just handed the decision back to users — the rest depends on whether each app can actually justify the "Allow" click. 好不好用,試了才知道.
Sources / 資料來源
- Apple says it's tightening macOS Full Disk Access controls due to new risks from AI agents - TechCrunch
- Apple Announces Full Disk Access Changes on macOS Due to AI Agents - MacRumors
- Apple is restricting full disk access on Macs due to concerns about AI agents - GIGAZINE
延伸閱讀 / Related Articles
- Pi 1.0評測:登頂HN的開源極簡Coding Agent | Pi 1.0 Review: The Minimalist Coding Agent Topping HN
- JADEPUFFER評測:全自動AI勒索軟體7分鐘血洗雲端 | JADEPUFFER Review: AI Ransomware Wipes Cloud in 7 Minutes
- GPT-6.1 Sol評測:價格僅Astra五分之一,效能打幾折? | GPT-6.1 Sol Review: Astra-Level Power, 1/5 the Price
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言