Meta is refuting the claims of a journalist. The journalist stated that the AI agent of Meta, Muse, read the private information of users without their permission. Previously, Jason Aten, a columnist for Inc, published a report detailing this issue. Subsequently, Andy Stone, the vice president of communications at Meta, responded, stating clearly that the company does not believe its products have ever done such a thing without user consent.
Stone responded to the relevant statements on X by writing: 'The integration of "information" in the Muse Mac application is entirely initiated by the user. You must enable both "Full Disk Access" and the "Information" connector of Muse for Muse to be able to read your "information" content. Unless you do so, it will not be able to read your "information.'"
Despite Meta denying it, many people still suspect that Meta has not provided a truthful account of the situation.
This is not surprising, as this tech giant has repeatedly mishandled consumer data over the years, leading to lawsuits, violations of regulations by the US Federal Trade Commission ( FTC ), and fines. Just a few days ago, a jury in New Mexico determined that this tech giant had misled users in its data handling practices. The case stemmed from the Cambridge Analytica data breach scandal in 2018.
Whether users trust Muse will determine whether Meta can win over the consumer market of AI. Although this app is currently performing well and still ranks first in App Store, if reports like these continue to emerge – regardless of their truthfulness – Meta's reputation may be difficult to recover. At the very least, the company should have communicated directly with this journalist to understand how such a situation could have occurred, rather than simply denying it.
Before the official statement from Meta, an executive from Meta Superintelligence Labs named David Singleton provided a more technical response. In Threads, he directly replied to Aten stating that if users want Muse to read their information on Mac, they must grant "three steps of permissions, which are located at the application layer and within the macOS system layer protection mechanisms." He said that even if there are vulnerabilities in the Muse application, these mechanisms "cannot be bypassed."
These steps include: the user must explicitly choose to grant Muse "full disk access" permissions; only thereafter can the user select what level of access to grant Muse for the "information" application, which can be "none," "read-only," or "read." If "full disk access" is not enabled, these options will appear grayed out and unavailable for selection.
In addition, when "full disk access" is allowed, a pop-up will display the macOS setup interface, and users must manually confirm again that they indeed wish to proceed with this action. Singleton states that this also triggers a full restart of the Muse application, thus reducing the likelihood of this option being inadvertently selected without the user's knowledge.
However, according to reports from Aten, when Muse read its information, "full disk access" was disabled. He also stated that when he asked Muse to explain how this situation occurred, AI claimed that it was synchronizing its "device notifications." Therefore, Aten believes that Muse may have passed on the banner notification text it received on Mac to this AI proxy.
Singleton also refuted this point, stating that AI was 'confused' at the time and gave a wrong explanation of what happened. Subsequently, he also mentioned the page on Meta regarding Muse's security architecture and vulnerability bounty process.
In short, the company's response is essentially that the situation described by Aten did not occur, and it is also impossible for it to have occurred.
This is not the only time that Muse has been accused of overstepping his bounds, and it is likely to be far from the last time as well. Another user, YouTuber Matt Robb, recently stated that Muse mishandled the process of helping him sell items through Facebook Marketplace, which resulted in his address being shared, and buyers came to his home when he was not there at all. According to Singleton's reply on Threads, he is clearly investigating this matter, which also implies that the company at least considers that this incident could be a problem on their end.











