Apple宣布将强化macOS中"完整磁盘访问"(Full Disk Access)功能的权限控制机制1。这一举措旨在应对AI代理软件带来的新型安全隐患1。
此前,Meta的Muse应用被指可能在未获得明确授权的情况下读取用户私密信息(Meta对此提出异议),而Wired报道则指出ChatGPT的Mac应用存在可能被黑客利用以窃取敏感数据的漏洞1。Apple在声明中表示,"一些开发者正在以可能危害用户系统中一切数据的方式使用完整磁盘访问,而用户并不充分了解"1。该功能允许应用访问文件、邮件、信息和浏览历史记录1。
Apple指出,"随着AI代理变得越来越强大和自主,与这一级别访问相关的风险将大幅增长"1。公司计划推出新的控制措施,确保用户只能通过"非常明确的用户操作"才能授予应用这一权限1。
Apple has announced plans to strengthen controls governing Full Disk Access on macOS, citing emerging security risks posed by increasingly autonomous AI agents 1. The decision follows reports that developers are leveraging this powerful permission in ways that could compromise user data without adequate user awareness 1.
The move comes after reports of security vulnerabilities in AI-focused applications. Meta's Muse app was reported to potentially read user private information without explicit permission, though Meta disputed the allegation 1. Additionally, Wired reported that ChatGPT's Mac application contains a vulnerability that could be exploited by hackers to access sensitive data 1.
Full Disk Access grants applications the ability to reach files, emails, messages, and browsing history 1. According to Apple, "some developers are using Full Disk Access in ways that could put everything on a user's system at risk, while users may not fully understand what is happening" 1.
Apple plans to implement new control measures that will require users to take "very explicit user actions" before granting applications this level of permission 1. The company stated that "as AI agents become increasingly powerful and autonomous, the risks associated with this level of access will grow significantly" 1.
评论
还没有评论,欢迎留下第一条。