Two reports published in recent days by TechRadar Pro shed light on the same trend: artificial intelligence assistants and agents are settling onto the workstation, and with them come new ways of exposing data. On one side, Apple says it wants to tighten the “Full Disk Access” permission in macOS. On the other, researchers at Huntress describe a campaign that hijacks custom GPTs hosted on ChatGPT to trap Windows users. Two very different mechanisms, which are worth understanding before drawing any conclusions.
Full Disk Access: a master key
On macOS, granting an application full disk access allows it to bypass a large part of the system’s privacy protections. It can then read files, documents, emails, messages, browsing histories and other data. This permission was designed in particular for backup software, which genuinely needs to be able to browse the entire machine.
In an announcement dated 2 October, Apple explains that some developers use this permission in a way that can expose the entire system, without users necessarily realising what they are granting. The company plans additional controls, so that an application only obtains this level of access after a very explicit action by the user. Apple directly cites the progress of AI agents among the reasons that make this change critical: the more autonomously a piece of software acts, the more serious the consequences of such broad access can be.
For now, nothing has changed in the interface. No timetable has been announced and, according to TechRadar Pro, there is no indication that the change is included in the macOS 27.2 betas. Betas 1 and 2 were, however, released before the announcement, which leaves the door open to a later integration.
The outlet notes that this decision may have been accelerated by an account published by Inc., according to which Meta’s Muse AI agent accessed a user’s messages. Andy Stone, a Meta spokesperson, pointed out on X that Full Disk Access and the Messages connector both require voluntary activation. The two claims are not mutually exclusive: it is precisely because activation is voluntary, but very broad, that the question of user understanding arises.
ClickFix: when the victim carries out the attack themselves
The second case does not rely on a misunderstood permission, but on the trust placed in well-known platforms. Custom GPTs are variants of ChatGPT configured for a specific task and hosted directly on chatgpt.com. Attackers created a fake assistant called “Plus 5.6”, a name modelled on the usual naming conventions of AI models.
The scenario described by Huntress unfolds in several stages:
- the GPT displays a single message: the main domain is supposedly experiencing limitations and the user must go through a backup domain;
- this backup domain is a page hosted on Google Sites, another legitimate service;
- the page presents a fake Cloudflare CAPTCHA that asks the user to copy a command, then paste it into the Windows Run dialog box;
- the supposed fix downloads and launches a remote access tool (RAT) identified under the name @input.
This is the principle of ClickFix: rather than exploiting a software flaw, the attack convinces the person to run the infection commands themselves. Once installed, the RAT can make it possible to view the screen, access the camera, microphone and system audio, search for files, collect information about the device, its protections and its network, and then download further payloads. According to the researchers, its communications are encrypted and designed to look like ordinary web traffic.
Huntress says it has observed several dozen occurrences, and its security operations centre has reportedly handled at least 40 cases. OpenAI helped remove a malicious GPT on 25 September; a new GPT based on the same principle was reportedly discovered as early as 27 September. Removing one assistant is therefore not enough to shut down the campaign.
What an SME can do right now
The two cases have one thing in common: they do not break any technical protection, they exploit consent given by the user. The measures below are a matter of common sense and follow directly from these mechanisms; they do not constitute an official recommendation.
- Take stock of full disk access on Macs. Check which applications have Full Disk Access and revoke this permission from those that have no obvious need for it, in particular recently installed AI assistants and agents.
- Grant the minimum necessary. Before connecting an AI agent to messages, email or files, ask yourself what data it really needs to see to do its job.
- Give teams a simple rule. No legitimate CAPTCHA, assistant or troubleshooting page asks you to paste a command into the Windows Run dialog box. Faced with such a request, stop and contact the person in charge of IT.
- Do not confuse a well-known domain with trustworthy content. A page on chatgpt.com or Google Sites may have been created by anyone. A service that redirects to a “backup domain” hosted elsewhere deserves suspicion.
- Favour AI tools chosen by the company. Stating clearly which assistants are authorised prevents everyone from going off in search of a GPT with a promising name.
None of this requires giving up AI tools. It is above all a matter of treating an agent like any powerful piece of software: you know what it can do, you limit what it has access to, and you teach employees to recognise an unusual request.
Sources
- “Apple to further restrict full disk access on Mac because of the risks linked to AI agents”, TechRadar Pro (France), 7 October 2026: global.techradar.com
- “A fake ‘Plus 5.6’ hosted on ChatGPT traps users with a fake CAPTCHA”, TechRadar Pro (France), 2 October 2026: global.techradar.com




