Meta introduced Muse this September, billing it as "a safe, secure, private, and widely available personal AI agent." However, journalist Jason Aten, testing the agent on a Mac mini and iPhone, discovered that Muse had read his private text conversation with a podcast cohost. When questioned, Muse stated that the Mac version read incoming notifications and shared that context with the Meta iPhone app.
Aten later found that Muse was syncing his local Messages database—up to row 187,462—contradicting its earlier claim of not having access to chat histories. He confirmed he had not granted Muse full disk access permissions, which should have been necessary to read the database.
David Singleton, CEO of Meta Superintelligence Labs, responded on social media with posts that appeared to blame Aten for the situation. It remains unclear how Muse gained access, and this incident is the latest in a string of privacy and security queries about the agent. Separately, it was also reported that Muse can run terminal commands on its server host, powered by AMD EPYC Turin systems.