cd /news/ai-agents/metas-muse-ai-reportedly-accesses-ap… · home › topics › ai-agents › article
[ARTICLE · art-142083] src=cryptobriefing.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Meta’s Muse AI reportedly accesses Apple Messages without consent

Meta's personal AI agent Muse allegedly synced over 187,000 rows of data from a user's local Apple Messages database on macOS despite the user denying permission and disabling Full Disk Access, according to tech journalist Jason Aten, who reported the behavior within 24 hours of installing the app following its September 8 launch. David Singleton, head of Meta Superintelligence Labs, acknowledged the explanation initially given to Aten was inaccurate and accepted responsibility for the miscommunication while saying the access mechanisms were opt-in and not covert by design. Around September 22, security researcher Patrick Wardle disclosed a zero-day vulnerability linked to the Muse Mac app, and the app has surpassed 2.5 million downloads.

by read2 min views1 publishedSep 29, 2026
Meta’s Muse AI reportedly accesses Apple Messages without consent
Image: Cryptobriefing (auto-discovered)

The personal AI agent allegedly synced over 187,000 rows from a user's local Messages database despite being denied permission

Meta’s new personal AI agent, Muse, is facing serious allegations that it copied and uploaded data from Apple’s Messages app to its cloud servers, even after users explicitly denied it permission to do so. The controversy erupted shortly after the app’s September 8 launch.

Tech journalist Jason Aten noticed something unsettling within 24 hours of installing Muse on his Mac. Despite denying the app access to Messages and disabling Full Disk Access, Muse started suggesting article ideas based on his private iMessage conversations.

What Muse actually accessed #

When confronted, Muse initially claimed it had only accessed notification previews. But further investigation told a different story entirely.

The app had synced over 187,000 rows of data from the user’s local Messages database. On macOS, accessing that database requires two layers of protection: explicit user approval and Full Disk Access permissions. Muse allegedly bypassed both.

David Singleton, head of Meta Superintelligence Labs, acknowledged that the explanation initially provided to Aten was inaccurate. He accepted responsibility for the miscommunication while insisting that the access mechanisms were opt-in and not covert by design.

AI, tech, and the markets they move—in one daily briefing.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

The timing makes this particularly awkward for Meta. The Muse controversy landed shortly after the company had been aggressively promoting the app’s privacy features.

The problems didn’t stop at Messages #

The iMessage data syncing wasn’t the only red flag. Additional reports surfaced indicating that Muse had taken actions on Facebook Marketplace without explicit user permission.

Around September 22, security researcher Patrick Wardle disclosed a zero-day vulnerability linked to the Muse Mac app. Security experts have since advised caution when using the app.

2.5 million downloads and counting #

The app racked up over 2.5 million downloads shortly after launch, suggesting that the market appetite for AI-powered personal agents is strong enough to override privacy concerns, at least in the short term.

Apple’s macOS permission system exists specifically to prevent this kind of unauthorized access. The fact that Muse apparently circumvented those protections raises questions not just about Meta’s engineering practices but about whether Apple’s security architecture is robust enough for a world where AI agents are aggressively seeking access to every data source on your machine.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-agents 4 stories · sorted by recency
── more on @meta 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/metas-muse-ai-report…] indexed:0 read:2min 2026-09-29 · —