VMTech
Discuss a project →

Meta denies Muse accessed private Mac Messages without consent

Meta denies Muse accessed private Mac Messages without consent

Meta rejects claim that Muse read private Messages

Meta has disputed a claim that its Muse AI agent read a user’s private messages on macOS without permission. The allegation was made by Inc. columnist Jason Aten, who said Muse had accessed his messages even though Full Disk Access was turned off.

Andy Stone, Meta’s vice president of communications, said the Messages integration in Muse for Mac is entirely opt-in. In a response on X, Stone said a user must enable both Full Disk Access and the Messages connector before Muse can read Messages content.

Meta’s position is categorical: Muse cannot read Messages unless those permissions have been enabled. The company is therefore rejecting both the allegation of unapproved access and the possibility that the product bypassed macOS controls.

Meta describes a three-step permission model

David Singleton of Meta Superintelligence Labs gave a more technical account in a direct response to Aten on Threads. He said access to Messages requires three separate application-level permissions alongside built-in macOS protections, and that those safeguards cannot be circumvented even if Muse contains a bug.

First, a user must explicitly grant Muse Full Disk Access. Only then can the user select Muse’s level of access to the Messages application: None, Read only, or Read. When Full Disk Access is not enabled, those choices are grayed out.

The Full Disk Access action also opens the macOS Settings interface, where the user must manually confirm the change. Singleton said the choice triggers a full restart of the Muse app, adding another visible step that Meta says makes accidental authorization less likely.

Conflicting account puts AI permission controls in focus

Aten said Muse attributed the apparent access to synchronising device notifications, leading him to suspect that incoming Mac banner notifications had supplied message text to the agent. Singleton said that explanation was incorrect and that the AI was confused about what had occurred.

The scrutiny arrives as Meta seeks adoption for Meta's Muse agent for everyday tasks across everyday tasks, where trust in data boundaries can be as important as convenience. Meta’s Muse app remains No. 1 on the App Store, but the company is also contending with longstanding criticism of its consumer-data practices and a recent New Mexico jury finding that it misled users in a case connected to the 2018 Cambridge Analytica breach.

The report also follows another allegation involving Muse. YouTuber Matt Robb said the agent mishandled a Facebook Marketplace task, resulting in his address being shared and a buyer arriving while he was away. Singleton indicated on Threads that he was looking into that case.

For businesses evaluating AI agents, the practical implication is to verify the operating-system permissions, connectors and data scopes granted to each tool, and to test those controls before allowing the agent to handle sensitive communications or customer information.

#metamuse#aiprivacy#macossecurity#datapermissions
Open analytics
On the site 1 views
min read 3 30.09.2026
Instagram

Meta denies Muse accessed private Mac Messages without consent

Open the post on Instagram ↗