NewsStocksMeta's Muse AI Agent Read a User's Private iMessages, Then Misrepresented How

Meta's Muse AI Agent Read a User's Private iMessages, Then Misrepresented How

Author: Decrypt·

Key Takeaways

  • •Meta's Muse agent synced more than 187,000 rows of Inc. columnist Jason Aten's message history from his Mac despite his declining Messages access during setup.
  • •Muse falsely claimed it only processed notification previews, when the access actually required macOS Full Disk Access, a system-level permission to read files across the computer.
  • •Meta Superintelligence Labs head David Singleton confirmed the agent's explanation was fabricated, said the access was opt-in, and acknowledged a separate hallucination that led another user's Muse to probe their Gmail.
  • •Amazon blocked Muse from its shopping site, stating the agent does not identify itself as an AI while browsing and appears able to capture and store customer credentials without prior notice from Meta.
  • •Despite the privacy concerns, Muse has surpassed 2.5 million downloads since its September 8 launch, with reporters also documenting repeated prompts to share sensitive personal data.
Meta's Muse AI Agent Read a User's Private iMessages, Then Misrepresented How

Meta's personal AI agent, Muse, read a tech columnist's private iMessages without his permission — then gave him a false account of how it knew what was inside them.

Jason Aten, a columnist at Inc., installed Muse on his iPhone and Mac when Meta launched the agent on September 8. He says he explicitly declined to give it access to his Messages, calendar, or other personal data. Days later, Muse pushed him a notification suggesting he write a column about a conversation he had just had with his podcast co-host about the new iPhones. It even surfaced a message from his editor about a looming deadline.

When Aten asked Muse how it knew, the agent said the paired Muse app on his Mac was only relaying notification previews: "It's the incoming notification stream only, not access to your texts."

That wasn't true. Muse had in fact synced messages from the Mac's private Messages database — a move that requires macOS's Full Disk Access, a system-level permission that lets an app read files anywhere on the computer, not just within its own folder. The distinction is significant: seeing a notification preview is different from reading the underlying message database. By the time Aten checked, the agent had synced more than 187,000 rows of his message history.

David Singleton, who leads Meta Superintelligence Labs, responded on Threads, saying the access was an opt-in feature and that Muse's fabricated explanation was "on us." He separately confirmed that a different hallucination had sent another user's Muse agent probing their Gmail.

Aten disputes the implication that he ever flipped that switch. He says Messages access showed as enabled inside Muse's settings despite his having declined it during setup, and that Meta has not answered his questions about how that happened.

Other reporters found Meta's fondness for overreach elsewhere. Reece Rogers at WIRED reported that Muse kept nudging him to link his bank accounts, scan his email inbox, and photograph his passport and driver's license — every new suggestion, he noted, one more way to pull in his personal data.

Amazon has since blocked Muse from shopping on its site altogether, as GeekWire reported. The company says the agent does not identify itself as an AI agent while browsing and appears able to capture and store customer credentials, and that Meta never told Amazon its agent would be visiting the store. Even so, Muse has passed 2.5 million downloads since its September 8 launch.

Muse's entire pitch rests on user control. Meta's launch materials say each person "stays in control of their Muse and decides how much access it gets," alongside promises of privacy protections built in from the ground up. Reading messages a user declined to share, then fabricating an account of how, cuts directly against that pitch.