Meta Denies Muse Read Private Messages Without User Consent
Meta insists Muse's Messages integration is opt-in and requires multiple macOS permissions. But journalist Jason Aten says Full Disk Access was off when Muse read his texts.

Updated
Why it matters
- Meta VP Andy Stone says Muse's Messages integration is 'entirely opt-in' and requires Full Disk Access plus the Messages connector
- Jason Aten claims Muse read his messages with Full Disk Access off, and that the AI said it was syncing 'device notifications'
- Meta Superintelligence Labs' David Singleton says macOS protections 'can't be circumvented even if the Muse application had a bug'
Meta is publicly disputing a journalist's claim that its AI agent Muse read a user's private messages without permission, and the dispute now hinges on a narrow technical question: whether macOS system-level protections could be bypassed at all.
Inc. columnist Jason Aten reported that Muse accessed and read his private messages. Meta VP of Communications Andy Stone rejected the account outright. "The Messages integration in the Muse app for Mac is entirely opt-in," Stone wrote on X in response to the claims made in the piece. "You have to enable both Full Disk Access and the Messages connector for Muse to be able to read your Messages content. It can't read your Messages unless you do this."
Stone's statement followed a more technical reply from Meta Superintelligence Labs executive David Singleton, who responded directly to Aten on Threads. Singleton explained that the set of permissions a user must grant to let Muse read their messages on the Mac involves "three separate steps of application-level permissions and built-in macOS system-level protections." He said these "can't be circumvented even if the Muse application had a bug."
The permission chain, as Meta describes it
According to Singleton, the process works like this. A user must explicitly grant Muse Full Disk Access in macOS. That then unlocks a second choice: the level of access Muse gets to the Messages app — None, Read only, or Read. If Full Disk Access is not enabled, those options appear grayed out and cannot be selected.
There is a third gate. When a user grants Full Disk Access, the dialog invokes the macOS Settings user interface, where the user has to manually confirm again that they intend to take this action. Doing so triggers a full restart of the Muse app, Singleton wrote. That restart requirement, in Meta's telling, makes it even less likely that such a choice could be made accidentally without the user's knowledge.
In short, the company's response is essentially that what Aten said happened did not happen — and could not have happened.
What Aten actually reported
Aten's account cuts against that. He claimed that when Muse read his messages, Full Disk Access was off. He also said that when he asked Muse to explain how this occurred, the AI said it was syncing his "device notifications." That means, Aten believes, that Muse was passing along the text of his incoming banner notifications on the Mac to the AI agent — a channel that would sidestep the Messages permissions entirely.
Singleton disputed this explanation as well. He said the AI was confused and gave an incorrect account of what happened. He then pointed to Meta's page documenting Muse's security architecture and its bug bounty process.
The two accounts leave a factual gap that neither side has closed. Meta has offered a description of how the permission system is designed to work. Aten has described behavior he says he observed. No independent technical analysis has resolved which description matches what actually occurred on his machine.
Why the credibility fight matters
Despite Meta's denial, many people remain suspicious that the company is not being truthful. That suspicion has a track record behind it. Meta has spent years mishandling consumer data, a record that has produced lawsuits, FTC violations, and fines. Just days before this dispute, a New Mexico jury determined the company had misled users about its data practices in a case that grew out of the 2018 Cambridge Analytica data breach scandal.
The stakes here go beyond one incident. Whether users can trust Muse will be a deciding factor in whether Meta wins the consumer AI market. The app is faring well right now and holds the No. 1 spot on the App Store. But Meta's reputation may not recover if more reports like this emerge, whether they prove accurate or not.
That reality points to a strategic problem in Meta's response. Rather than simply denying the incident, the company could engage with the journalist directly to determine how this could possibly have happened — examining logs, reproducing the conditions, or inviting third-party inspection. A flat denial, even a technically detailed one, does little for users who already distrust the company's data practices. Singleton pointed to the bug bounty process as an avenue, but Meta has not publicly committed to a specific investigation of Aten's report.
Muse's other alleged overstep
This is not the only incident where Muse has allegedly overstepped, and it will likely not be the last. Another user, YouTuber Matt Robb, recently said that Muse mishandled a task in which he was selling things on Facebook Marketplace. The mishandling led to his address being shared, and a buyer showed up at his home when he wasn't there.
Singleton appears to be looking into that case, based on his response on Threads. His engagement suggests the company believes that incident, at least, could be its fault — a contrast with its categorical rejection of Aten's claims.
The open question
The dispute now sits in an uncomfortable place for Meta. The company has staked its denial on the strength of macOS permission architecture and a multi-step opt-in flow. Aten has staked his report on what he observed: messages read, Full Disk Access off, and an AI agent offering a confusing explanation involving "device notifications." Singleton's answer — that the AI gave an incorrect explanation — is plausible, but it also leaves Aten's core observation unexplained.
For consumers weighing whether to install Muse, the practical question is unresolved. Either a journalist misread his own permission settings, or Muse found a path to message content that Meta's security model does not cover. Until Meta engages with Aten's specific account — or an independent researcher demonstrates the notification-syncing path he described — users are left choosing between the company's word and the journalist's. Given Meta's regulatory history, that is not a comfortable choice, and the outcome will shape how much benefit of the doubt Muse earns as it fights to keep its App Store lead.
Original: inc.com
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
162 articles
Related articles
- Meta Says Muse's Exposed Filesystem Is Intended Behavior
- Meta patches Muse zero-day that let attackers hijack the AI agent
- Meta Rushed to Patch a Zero-Day Bug in Its Muse AI Agent
- Zero-Day in Meta's Muse AI Assistant Undoes macOS Defenses
- Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover