Meta disputes report over Muse reading Mac Messages

Meta says Muse on Mac needs multiple user permissions to access Messages, after a report claimed the app read private chats without consent.
Meta is pushing back after a report claimed its Muse AI app on Mac read a user’s private Messages without permission. The company says that is not possible without explicit consent, but the dispute has already revived broader doubts about how much users should trust Meta with personal data. That matters because Muse is part of Meta’s consumer AI push, and privacy concerns could affect whether people keep using it.
Meta says Muse needed several permissions
Meta VP of Communications Andy Stone said the Messages integration in the Muse app for Mac is “entirely opt-in.” According to him, users must enable both Full Disk Access and the Messages connector before Muse can read Messages content.
Stone said Muse “can’t read your Messages unless you do this,” directly rejecting the claim made in the report by Inc. columnist Jason Aten.
Meta’s response makes its position clear: the app did not secretly access private conversations, the company says. Instead, Meta argues that the feature works only when a user has deliberately turned on the required permissions.
Meta points to macOS protections
Meta Superintelligence Labs executive David Singleton offered a more technical explanation on Threads. He said the process involves “three separate steps of application-level permissions and built-in macOS system-level protections,” and that these protections “can’t be circumvented even if the Muse application had a bug.”
Singleton described a sequence in which the user first has to grant Muse Full Disk Access. Only then can the user choose how much access Muse gets to the Messages app, with options such as None, Read only, or Read. If Full Disk Access is not enabled, those options are grayed out.
He also said that when Full Disk Access is being enabled, macOS opens its own Settings interface, where the user must confirm the action again manually. That step, according to Singleton, triggers a full restart of the Muse app, making accidental access less likely.
Meta also pointed to its page about Muse’s security architecture and bug bounty process. As IT-PUB News notes, that documentation was part of the company’s effort to support its explanation of how the app handles access.
The journalist says Full Disk Access was off
Aten’s report, though, described something different on his machine. He said Muse read his messages even though Full Disk Access was off.
He also wrote that when he asked Muse to explain what happened, the AI replied that it was syncing his “device notifications.” Aten believes that could mean Muse was passing the text of incoming banner notifications on the Mac to the AI agent.
Singleton disputed that explanation too, saying the AI was confused and gave an incorrect account of what happened.
At this point, the disagreement is no longer just about interpretation. The two sides are describing very different versions of how the same feature behaved, which is why the issue has drawn attention beyond a single user report.
Trust remains a problem for Meta’s AI push
The dispute is landing at a sensitive moment for Meta. The company has spent years dealing with criticism over consumer data practices, along with lawsuits, FTC violations, and fines. Just days before this exchange, a New Mexico jury determined that Meta had misled users about its data practices in a case tied to the 2018 Cambridge Analytica data breach scandal.
That history helps explain why even a technical argument about permissions is being watched closely. For many users, the question is not just whether Muse requires the right settings, but whether Meta can convincingly show that those safeguards always work as described.
The concern is practical as well as reputational. If people believe an AI app may be able to see private messages or notifications without clear permission, they may hesitate to use it for everyday tasks. That could become a real obstacle for Meta as it tries to compete in the consumer AI market.
Muse has faced other complaints too
This is not the first time Muse has been accused of overstepping. Another user, YouTuber Matt Robb, recently said Muse mishandled a Facebook Marketplace task in a way that exposed his address and led a buyer to show up when he was not home.
Meta looked into that case, and the source says it was complicated. The user later admitted that he had granted a permission that allowed the problem to happen, and the article was updated to reflect that.
Even so, the two incidents together help explain why Muse is being scrutinized so closely. When an AI assistant is allowed to act across a user’s apps and data, small permission mistakes can have real-world consequences. In one case, that could mean confusion over private messages. In another, it could mean a home address being shared in a marketplace transaction.
For Meta, the immediate challenge is not only whether it is technically right in this dispute, but whether it can persuade people that Muse behaves predictably and safely. That question remains unsettled.