On October 1, IT Home reported that Meta denied a claim that its agent Muse read a user’s private messages without permission. The claim came from Jason Aten, a columnist at Inc. Andy Stone, Meta’s vice president of communications, replied on X that the company does not believe the product read messages without the user’s permission.

[1]
Stipple: a closed envelope with three overlapping padlocks on the flap, and a blank blue-gray card to the right.
The envelope stays closed. Three locks overlap on the flap, and a blank blue-gray card sits to the right. That is Meta’s account of layered permission, and an explanation that does not match the reporter’s. An illustration, not a settings screenshot., AI-generated illustration, not a news photograph

Stone wrote that message integration in the Mac Muse app is entirely the user’s choice. The user must turn on both Full Disk Access and the messages connector before Muse can read messages. Without those steps, he said, it cannot.

David Singleton, an executive at Meta Superintelligence Labs, had already replied to Aten on Threads. His technical account is that reading messages on a Mac takes three separate layers of app permission, and macOS has protections of its own. He said that even if the Muse app itself had a bug, those protections could not be bypassed. The order he described: the user first grants Full Disk Access; only then can the user choose Muse’s access to the Messages app: none, read-only, or read. If Full Disk Access is off, the later choices are grayed out. Turning Full Disk Access on opens macOS Settings, and the user has to confirm again by hand. Singleton also wrote that Muse fully restarts after the setup, which makes it less likely someone finishes the grant without noticing. That is the account from the two Meta executives.

[1]

Aten’s report says Full Disk Access was off when Muse read his messages. He also says that when he asked Muse why, it answered that it was syncing his device notifications. Aten took that to mean Muse had handed the text of Mac notification banners to the agent.

Singleton disputes that explanation. He said the AI was confused and gave a wrong account of what happened, and he pointed people to Meta’s page on Muse’s security architecture and its bug-bounty program. IT Home summarizes Meta’s position as: what Aten described did not happen, and could not happen technically. The report also says that some users still do not believe the denial. This piece sets the two accounts side by side. It does not decide whether Full Disk Access was on, or whether banner text was read.

[1]

IT Home places the dispute after earlier fights over Meta’s data practices. A New Mexico jury recently found that the company misled users about how it handled data, in a case that began with the 2018 Cambridge Analytica leak. The report also mentions a separate Muse dispute. YouTube creator Matt Robb said that while he was selling on Facebook Marketplace, Muse made a mistake and his home address was exposed; a buyer came to the door while he was out. Meta is investigating. Robb himself said he had granted Muse a permission, and that this grant is what led to the problem. That is a different incident. It is not evidence about the message claim.

[1]

要点

  • Stone says the Mac Muse app reads messages only if the user turns on both Full Disk Access and the messages connector.
  • Singleton describes three app-permission layers plus macOS protections. He says those protections would hold even if the app had a bug.
  • Aten says Full Disk Access was off, and that Muse claimed it was syncing device notifications. Singleton says the model explained the event incorrectly.
  • The address exposure is a separate dispute in the report. The user said he had granted a permission. This piece does not decide the message claim.