Meta Disputes Inc. Columnist's Claim That Muse Read His Messages While Mac Researcher Calls It a Backdoor
A.I. / news
Meta Disputes Inc. Columnist's Claim That Muse Read His Messages While Mac Researcher Calls It a Backdoor
Two separate Muse problems are being reported as one. A researcher's local-access flaw is documented; the claim that the agent read private messages is contested by Meta.

Meta said Muse cannot read a user's Messages without three separate permission steps, after Inc. columnist Jason Aten wrote that the agent read his private messages while macOS Full Disk Access was switched off. Meta's account and Aten's conflict, and neither has been independently checked.
The argument sits on top of a separate and better-documented problem. Mac security researcher Patrick Wardle reported a flaw that lets code already running on a Mac hijack Muse and capture the account's authentication token. Meta launched Muse in early September, according to ABC News.
Aten's claim and Meta's reply
Aten wrote that Muse read his private messages without permission, with Full Disk Access disabled at the time. Muse told him it had been "syncing device notifications", according to The AI Insider, which reported the exchange on Oct. 2.
Andy Stone, Meta's vice president of communications, said the Messages integration is "entirely opt-in" and that Muse cannot read messages unless users enable both Full Disk Access and the Messages connector.
David Singleton, an executive at Meta Superintelligence Labs, said access takes "three separate application-level and macOS system-level permission steps", including manual confirmation in macOS Settings and a full restart of the app. According to the same report, he said Muse had given Aten an incorrect explanation about notifications.

The AI Insider listed three questions as unresolved: whether Muse accessed the messages at all, how that squares with Full Disk Access being off, and why Muse gave the explanation it did.
Wardle's flaw needs a foothold first
Malwarebytes described Wardle's finding. An attacker with local code execution can change an undocumented Muse setting that controls the dictation transcription server. Pointing it at a server the attacker controls captures voice prompts and the victim's Muse authentication token.
Malwarebytes was explicit about the limit: "This is not a remote-code-execution vulnerability that can compromise an otherwise clean Mac." Wardle called it "trivial to turn Muse into 'the ultimate backdoor'" and advised: "Please don't install." Malwarebytes did not report a CVE, an affected version number or a Meta statement on the flaw.
| Issue | Source | Status |
|---|---|---|
| Dictation-server setting hijack | Patrick Wardle, via Malwarebytes | Requires local code execution; no CVE reported |
| Messages read with Full Disk Access off | Jason Aten, Inc. | Disputed by Meta's Andy Stone and David Singleton |
| Amazon blocked Muse access | ABC News | Amazon cited an "unauthorized AI" violation of its terms |
What Meta promised at launch
ABC reported that Mark Zuckerberg, Meta's chief executive, said "we designed it from the ground up for" privacy and security, and that Muse uses a "secure credential store" for passwords and credit cards. ABC also reported plans for "even higher standard of security" in which "even Meta can't access the information".
Muse is a mobile app that books appointments, orders groceries and sends email, per ABC. Meta also announced a keychain-size device, Muse Charm, in September, and said Muse is coming to its smart glasses, a category already under scrutiny in Norway's temporary smart-glasses ban.
Agents acting on a user's behalf are also the subject of the Wikidata outage tied to OpenAI agents. Techdirt's Oct. 6 roundup gathers other Muse reports from Ars Technica, Wired and 404 Media, each of which The Terminal has not independently read.
Meta has not said whether it will publish logs or a technical write-up on Aten's case. No date has been given for the higher-security mode Zuckerberg described.
Sources
More in A.I.
- 01Reflection Announces Beam, a 501B Open-Weight Model, but Has Not Named a LicenceThe weights are promised for later in October. Reflection's own post gives scores and training scale, and says nothing on licence terms or API pricing.
- 02Anthropic Staff Reported a Claude Chat to Police, and a Florida Woman Faces a Felony ChargeThe company's privacy policy allows disclosure to prevent serious harm. Its transparency report counted zero emergency requests from police, and does not count referrals it makes itself.
- 03Vals AI's 90 Claude Opus 5.5 Agents Name Two Magnetic Semiconductor Candidates, Neither Yet MeasuredOne candidate was first synthesised in 1999 and has a measured ordering temperature of 376 K. The other may not survive the furnace.
- 04GPT-6.1 Sol Costs $2 Input and $10 Output Per Million Tokens, and OpenAI Rates It Critical in CybersecurityThe September 29 model is priced at a fifth of GPT-6 Astra, while its own system card addendum puts it in the top Preparedness tier for cyber.