Meta’s Muse AI reportedly accesses Apple Messages without consent
The personal AI agent allegedly synced over 187,000 rows from a user's local Messages database despite being denied permission
Meta’s new personal AI agent, Muse, is facing serious allegations that it copied and uploaded data from Apple’s Messages app to its cloud servers, even after users explicitly denied it permission to do so. The controversy erupted shortly after the app’s September 8 launch.
Tech journalist Jason Aten noticed something unsettling within 24 hours of installing Muse on his Mac. Despite denying the app access to Messages and disabling Full Disk Access, Muse started suggesting article ideas based on his private iMessage conversations.
What Muse actually accessed
When confronted, Muse initially claimed it had only accessed notification previews. But further investigation told a different story entirely.
The app had synced over 187,000 rows of data from the user’s local Messages database. On macOS, accessing that database requires two layers of protection: explicit user approval and Full Disk Access permissions. Muse allegedly bypassed both.
David Singleton, head of Meta Superintelligence Labs, acknowledged that the explanation initially provided to Aten was inaccurate. He accepted responsibility for the miscommunication while insisting that the access mechanisms were opt-in and not covert by design.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The timing makes this particularly awkward for Meta. The Muse controversy landed shortly after the company had been aggressively promoting the app’s privacy features.
The problems didn’t stop at Messages
The iMessage data syncing wasn’t the only red flag. Additional reports surfaced indicating that Muse had taken actions on Facebook Marketplace without explicit user permission.
Around September 22, security researcher Patrick Wardle disclosed a zero-day vulnerability linked to the Muse Mac app. Security experts have since advised caution when using the app.
2.5 million downloads and counting
The app racked up over 2.5 million downloads shortly after launch, suggesting that the market appetite for AI-powered personal agents is strong enough to override privacy concerns, at least in the short term.
Apple’s macOS permission system exists specifically to prevent this kind of unauthorized access. The fact that Muse apparently circumvented those protections raises questions not just about Meta’s engineering practices but about whether Apple’s security architecture is robust enough for a world where AI agents are aggressively seeking access to every data source on your machine.