Claude catches root malware on Stratechery's Mac Mini, as Apple tightens AI agents' Full Disk Access
- Stratechery's always-on Mac Mini, which runs nothing but Claude and Codex, was rooted through CVE-2026-65400, a macOS screen sharing state-management bug rated 7.1 out of 10 that Apple patched for Tahoe, Sequoia, and Sonoma; attackers took root and planted a Monero miner on machines with port 5900 exposed to the internet.
- Claude's scheduled restart of its monitor tool fired an urgent alert: a hook in /etc/zshenv was launching /var/tmp/.xmr with admin rights, both files owned by root and dated Dec 31 1969, and the account could now run admin commands without a password. Claude stopped executing all commands and changed nothing.
- The author ignored Claude's recommendation to stop using it and instead had the agent find the exact four-second window when the intruder gained access, build a tool to watch for it, and then wiped the Mac Mini.
- Apple says some developers use Full Disk Access in ways that expose files, mail, messages, and browsing history without users understanding, and that the risks grow as AI agents become more capable and autonomous.
- The Hacker News thread ties Apple's move to Meta's Muse agent, which sent columnist Jason Aten an unsolicited notification about an Apple Messages thread he never granted it access to, two weeks before Apple's announcement.
Hacker News opinions
I don't get the reaction to Apple making Full Disk Access more explicit. Whether they're happy or sad about agents isn't the point at all. Stripping full system access from non-deterministic tools that fall for prompt injection is the obvious move, and I run everything in rootless containers these days.
This is about platform control, not emotion. Apple limits background autonomy under the security label while its own system frameworks keep ambient access. Standard playbook.
Full Disk Access isn't reserved for Apple. You can grant it to any app, and nothing Apple said suggests they're taking that permission class away. They just want users to understand what they're handing over.
He buried the lede and then finally asked it. If consumers get used to the freedom and the spying of products like Muse, Apple's privacy mandate gets very hard to hold. Bigger risk for Apple than people assume.
Apple's own statement says developers use Full Disk Access in ways that expose files, mail, messages, and browsing history, and that it can compromise the privacy of the people you message. That's the whole reason they're doing this.
Then it's their own dang fault. Modern macOS is a mess of update nags and permission prompts. We want sandboxing and security patches, but the UX around it is abominable.
Full Disk Access is what you give backup software. Give it to Meta's software on your main machine and Meta won't respect your privacy. Aten got an unsolicited Muse notification referencing a Messages thread he never granted it access to.
Counterpoint: Full Disk Access goes way beyond backup apps. I've given it to disk utilities, Sketch, and Terminal so I'm not drowning in permission requests while moving around my drives. If Apple limits it to backup apps, that breaks real work on a Mac.
Couldn't you just give agents access to the screen sharing software so they can see the TCC prompts? TCC has some synthetic click detection, so clicking Allow with osascript doesn't reliably work.
This brought to mind Neal Stephenson's 'Unix: The Hole Hawg of Operating Systems' from 1999. Power tools do real work, and they also spin you around and crush your hand against a joist.
I needed Full Disk Access just to call tmutil enable/disable for a Time Machine on/off switch. One command, no access to any of my data, still gated. If Apple rethinks this permission, hopefully they build finer-grained controls.
Another case of this is why we can't have nice things. App developers feel entitled to everything on the user's machine without getting consent, so now we get consent walls everywhere.