Unsurprisingly, Meta's new Muse AI agent blatantly ignores users permissions
dkobia
154 points
40 comments
September 29, 2026
Related Discussions
Found 5 related stories in 84.2ms across 8,041 title embeddings via pgvector HNSW
- Meta's New Muse AI Agent Read My Private Messages. I Never Asked It To frizlab · 11 pts · September 22, 2026 · 70% similar
- Amazon blocks Meta’s new Muse AI agent from shopping on amazon.com simianwords · 145 pts · September 21, 2026 · 66% similar
- Meta’s Muse has a serious 0-day pavel_lishin · 117 pts · September 22, 2026 · 65% similar
- Muse, the band, lost its social media handles to Muse, Meta's new AI agent _djo_ · 174 pts · September 09, 2026 · 64% similar
- Muse – Meta’s personal AI agent yks · 434 pts · September 08, 2026 · 64% similar
Discussion Highlights (11 comments)
ParanoidShroom
How is this possible? Apple messages are just free for anyone to read?
VCFundedGenYer
I think what’s more alarming is the macOS nannying UAC-like toggles to block disk access and other “protections” are apparently all UX reducing flash and no actual functionality. I’d argue this is a five alarm fire for macOS and Meta simply exploited it.
jkingsman
I'm no evangelist for LLM assistants, but this seems incredibly improbable and represents a failure of MacOS security if so. If full disk access isn't granted, Mac blocks it from the Downloads folder, to say nothing of actually sensitive paths. I would expect a far more likely case of an accidentally granted permission on another device or a permission that was on and then turned off. Permissionless action is about to skyrocket as an issue, but this particular scenario strikes me as incredibly unlikely. Would be interested to know if Muse can provide more meaningful data provenance/logs. Scanning iMessage dbs as a passive part of full disk access (and not a messages grant), if true, is a little sketchy, regardless.
bethekidyouwant
How is this a story anybody who knows how a computer works knows this is nonsense.
iamacyborg
The story from Hunterbrook is also pretty crazy with Muse having much more access to Meta’s social graphs than I suspect most users would hope. https://hntrbrk.com/breaking-news/muse-doxxing
mock-possum
> Meta says that Muse has to obey permissions that users set up. It won't access any data you don't explicitly allow it to access. Is this a setting configured in Muse itself? > It took Meta a single day to begin "helpfully" pitching article ideas based on texts he'd sent to a podcast co-host. When he asked Muse how it got the information, it said that it read banners from incoming texts. But that's not true, either.bAfter doing a little digging, Aten says Muse synced 187,000 lines from his Messages database, despite Full Disk Access being off. Is full disk access enforced on the OS side, or the app side? Like is this claiming MacOS security was breached by Muse somehow acting in spite of deliberately disabled access somehow? Has this been reproduced / recorded?
SamInTheShell
These companies don't care. The technology exists, but the legislative stick just isn't there to incentivize these idiots to do the right things.
cleandreams
I think the fundamental problem is that AI companies have been assuming that reinforcement learning with human feedback is an adequate foundational technology for guardrails. And that simply isn’t true.
SaucyWrong
The user is nothing but a mark to Meta. If you use anything they make, they have you. Someday I hope more people realize this.
drdexebtjl
A lot of comments saying this must not have happened because of macOS app permissions. That system is completely broken. Open your terminal app and run /Applications/Firefox.app/Contents/MacOS/firefox This opens a normal-looking Firefox window, but it has whatever permissions you gave to the terminal , which likely has Full Disk Access. It’s insane.
dvirdaniel3141
yeah the sandbox vs usefulness trap is the whole game. people will click allow all just to get the task done.