Meta Says Muse Cannot Read Mac Messages Without User Permission

The420.in Staff
5 Min Read

Meta has rejected an allegation that its AI agent Muse accessed a user’s private messages without permission. The company said that Muse’s Messages integration on Mac depends entirely on user authorization and that the application cannot access Messages content without the required system permissions. The dispute emerged after a journalist alleged that Muse had read his private messages even though he had not granted permission for such access.

What Does Meta Say About the Allegation?

Meta Vice President of Communications Andy Stone responded to the claim on social media, saying that the Messages integration in Muse for Mac is entirely opt-in. According to him, users must first grant Muse Full Disk Access and then enable the Messages connector. The company maintains that Muse cannot access a user’s Messages content without these permissions.

David Singleton, an executive at Meta Superintelligence Labs, also provided a technical explanation. He said that allowing Muse to read Messages on a Mac involves multiple application-level permissions as well as built-in macOS system protections. According to Singleton, these safeguards cannot be bypassed by a bug within the Muse application.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

What Permissions Does Muse Require?

According to Meta, users must first explicitly grant Muse Full Disk Access. They can then choose the level of access Muse receives to the Messages application. The available options include no access and different levels of reading access. If Full Disk Access has not been enabled, these options remain unavailable.

The process of granting Full Disk Access also requires users to confirm the action through the macOS Settings interface. Singleton said that once the permission is granted, the Muse application undergoes a complete restart. Meta argues that the multiple steps involved make it highly unlikely that such permissions could be granted accidentally without the user’s knowledge.

Also Read: https://the420.in/meta-muse-ai-agent-security-flaw-private-data/

What Did the Journalist Claim?

However, the journalist involved in the dispute claimed that Muse had read his Messages while Full Disk Access was turned off on his Mac. He also said that when he asked Muse to explain how the access had occurred, the AI responded that it was syncing his “device notifications.” The journalist believed that Muse may have been receiving the text of incoming notification banners displayed on the Mac.

Meta disputed this explanation as well. Singleton said the AI had provided an incorrect or confused explanation of what had happened. He also pointed to information about Muse’s security architecture and the company’s bug bounty programme.

Meta’s current position is therefore that the incident could not have occurred in the manner described by the journalist under the application’s stated permission and security model. The user’s account of the incident and Meta’s technical denial remain different explanations of what happened.

Has Muse Faced Another Privacy Concern?

Muse has faced another reported privacy-related issue involving a different user. YouTuber Matt Robb said that while using Muse for a task related to selling an item on Facebook Marketplace, the AI agent handled the task in a way that resulted in his address being shared with a buyer.

The buyer subsequently arrived at his home when Robb was not there. Meta investigated the incident. It was later acknowledged that the user had granted a permission that had enabled the situation to occur.

Why Does the Dispute Matter for AI Agents?

The dispute over access to private messages and personal information comes as AI applications increasingly gain the ability to interact directly with computers and other digital resources. The incident highlights the importance of clear user permissions, operating-system safeguards and transparency about how AI agents access and process personal data.

The420 Takeaway

As AI agents gain access to messages, files and other personal information, permissions become a critical security boundary. Users should review exactly what an AI agent can access before enabling connectors, while developers need to make those permissions and their consequences clear and verifiable.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected