Meta is pushing back against a journalist’s claim that its Muse AI agent accessed private messages on a Mac without permission, saying the feature requires users to manually enable multiple permissions before Muse can read their Messages content.
The dispute began after Inc. columnist Jason Aten reported that Muse had accessed his private messages even though he believed he had not granted the necessary permissions. Meta VP of Communications Andy Stone rejected the claim, saying the Messages integration in the Muse Mac app is completely opt-in.
Stone said users must enable both Full Disk Access and the Messages connector before Muse can access content from Apple’s Messages app. Without those permissions, he said, Muse cannot read Messages content.
Meta Superintelligence Labs executive David Singleton provided a more technical explanation, saying users must go through three separate application-level and macOS system-level permission steps before Muse can access messages. According to Singleton, those protections cannot be bypassed even if Muse itself contains a bug.
The process begins with users explicitly granting Muse Full Disk Access. They can then choose the level of access Muse receives to the Messages app, including no access, read-only access, or read access. If Full Disk Access has not been enabled, those options remain unavailable.
Granting Full Disk Access also requires users to confirm the decision through macOS Settings. Singleton said the Muse app then needs to restart, making it less likely that the permissions could be enabled accidentally.
Aten, however, said his experience was different. His report claimed that Full Disk Access was disabled when Muse accessed his messages. When he asked Muse how it had obtained the content, the AI reportedly said it was synchronizing device notifications.
Aten believes this could mean Muse was receiving text from incoming notification banners displayed on his Mac rather than accessing the Messages database directly.
Singleton disputed that explanation, saying Muse had become confused and provided an incorrect answer about what had happened. He also directed users to Meta’s documentation covering Muse’s security architecture and bug bounty program.
Meta’s position is that the behavior described in Aten’s report should not be possible under the permissions system built into Muse and macOS. The company says users must explicitly grant the required permissions before the AI agent can access Messages content.
The controversy comes as Meta continues expanding Muse as part of its consumer AI strategy. The incident could raise additional questions about how users understand the permissions granted to AI agents, particularly when those agents can interact with applications and information stored on personal computers.
Another recent incident involving Muse involved YouTuber Matt Robb, who said the AI mishandled a Facebook Marketplace task and resulted in his address being shared with a buyer. In that case, Robb later acknowledged that he had granted Muse a permission that allowed the incident to occur.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The separate cases highlight the importance of understanding exactly what permissions AI agents receive when they are connected to applications and services. Meta says Muse’s security controls are designed to prevent unauthorized access, while individual reports have raised questions about how the system behaves in real-world situations.



