The permissions Meta says Muse needs
Meta Superintelligence Labs head David Singleton responded first on Threads, saying Muse needs “three separate steps involving app-level permissions and macOS system protections” to access messages on a Mac. He said the restrictions cannot be bypassed, even if the Muse app has a bug.
The steps, as Singleton described them, are:
Meta spokesperson Stone later responded to Athen’s post on X, emphasizing that Muse cannot read messages without those permissions. Singleton also pointed to Meta’s page on Muse’s security architecture and its bug bounty program.
Athen said Muse read his messages despite Full Disk Access being off. Asked to explain what happened, the AI said it had synced “device notifications.” Athen suspected it had passed the text of incoming Mac notification banners to the AI. Singleton disputed that account too, saying Muse had become confused and described the event incorrectly.
The answer leaves a gap
Meta’s position is clear: the event Athen described did not happen and could not have happened. But the company has not publicly explained why Muse gave the notification-sync account, or what Athen saw that led him to believe his messages had been read.
That distinction matters beyond this report. Meta’s handling of user data has drawn criticism for years, along with lawsuits, Federal Trade Commission violations and fines. Days ago, a New Mexico jury found that Meta had misled users about its data practices in a case tied to the 2018 Cambridge Analytica data scandal.
Other Muse complaints add to the scrutiny. YouTuber Matt Robb said Muse mishandled a task involving selling items on Facebook Marketplace, exposing his address; a buyer then arrived while Robb was away. Singleton appeared to be investigating that case on Threads. Meta’s response may indicate it believes the company was at fault, at least in that instance.
Meta’s Muse app is performing well and remains No. 1 in the App Store. But adoption depends not only on whether the agent works; it also depends on whether users trust what it can access. I think the more important omission is a direct account of how this incident could have occurred, not another restatement of the permission model. If similar reports keep surfacing, they could damage that trust whether or not each one is confirmed.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X