Meta denied that its Muse AI agent read private messages on a Mac without user consent, responding to a report by journalist Jason Aten, who said that the agent accessed his messages despite the required Full Disk Access setting being disabled, according to his account.
Andy Stone, Meta’s vice president of communications, said that the Messages integration within the Muse app for Mac is entirely optional and requires both Full Disk Access and the Messages connector to be enabled. He added that Muse cannot read message content without completing these steps.
What permissions are required?
David Singleton, an executive at Meta Superintelligence Labs, provided a more detailed technical explanation. According to him, access to messages depends on three separate stages of app permissions and built-in macOS protections, and they cannot be bypassed even if there is a software bug in Muse.
The process begins by granting Muse Full Disk Access, followed by selecting the level of access to the Messages app: no access, read-only, or read. These options remain disabled if the first permission has not been enabled. Granting Full Disk Access also opens the macOS settings interface, where the user must manually confirm the action once more, followed by completely restarting the Muse app.
The dispute over the source of the messages
Aten said that Muse read his messages while Full Disk Access was disabled. When he asked the agent for an explanation, it replied that it had been syncing “device notifications,” leading the journalist to believe that the text of pop-up notifications on the Mac may have reached the agent instead of its reading the message database directly.
Singleton rejected this explanation as well, saying that Muse gave an incorrect or confused answer about what happened, and referred to Meta’s page on its security architecture and vulnerability-bounty program. The company’s position is therefore that the scenario described by Aten did not occur and that the permission mechanism makes it impossible.
Why does this dispute matter?
Meta’s denial alone does not settle why message content appeared in Aten’s experience, but it identifies the key point for review: Did the content arrive through explicit permission, through device notifications, or did the agent misdescribe the source of the data? The text provides no independent evidence that resolves any of these possibilities, nor does it mention a published technical investigation matching system logs against the user’s account.
The issue is increasingly important because AI agents do more than display information; they interact with applications and local data on the user’s behalf. As a result, the interpretability of the data source, clarity of permissions, and ability to audit what the agent actually read become practical factors in evaluating security and privacy, alongside the mere presence of a consent screen.
The article points to another incident in which a user, Matt Robb, said that Muse mishandled a selling task through Facebook Marketplace, resulting in his address being shared and a buyer arriving while he was not home. Updates stated that the user acknowledged part of the responsibility, while Meta said that the case was complex and that the permission granted contributed to what happened. This incident does not prove the existence of the same flaw, but it illustrates that risks can also result from valid permissions being used in a context the user did not anticipate.
By contrast, the author believes that user trust will be a decisive factor in Muse’s success and that repeated reports of similar incidents could harm Meta’s reputation even if it later turns out that each case did not represent a technically proven breach. The open questions in this story remain tied to actual access logs, the behavior of macOS notifications, and Meta’s ability to provide a verifiable explanation rather than simply issuing a denial.