Behavior of Meta’s Muse AI agent✴ Questions were once again raised about his safety. The agency had previously provided its user’s home address to an unidentified person without permission and even arranged to meet him. Now, the AI agent is accused of being able to access iPhone and Mac users’ personal information without authorization.
Image source: AI
While many people who have tested Muse have spoken positively about the AI agent, it turns out it doesn’t offer as much privacy as Meta claims✴. The company claims Muse is “Building a personal artificial intelligence agent from the ground up that is safe, secure, private, and publicly accessible”. However, he was found to have viewed thousands of personal messages without permission.
Jason Aten via publication company Tested Muse on Mac mini and iPhone. He uses the Mac mini exclusively to test new agents like Muse. After installing the program, Aten starts assigning it simple tasks. The agent said he could help come up with ideas for new articles. But then Muse did something unexpected, coming up with a topic based on information it shouldn’t have access to.
According to Aten, he corresponded with the podcast co-hosts about the new iPhone 18 Pro and his decision to stick with last year’s model. Communicate in text format through messaging apps. At some point, Muse stepped in and offered to write an article on the topic, and also volunteered to do additional information gathering. The problem was that Aton did not grant the Muses permission to read his messages.
When asked how he knew about the conversation, the AI agent responded that the Mac version of the app was able to read incoming notifications. The message is then transferred to the Meta application✴ For iPhone, Muse came up with the idea for this article. Aton had no idea such a thing was possible, let alone that Muse was actually doing it. The AI agent claimed that it did not read Aten’s messages itself and had no access to communication history. However, reporters were not convinced by these explanations.
After careful inspection, Aten found that Muse had indeed synchronized the local message database. Additionally, the synchronization process reached line 187,462 of the database, indicating that Muse could access communication history, despite the developer’s assurances to the contrary.
Aten confirmed that he did not grant Muse access to the entire drive on his Mac, which is required for the agent to read the messaging application’s database. The reporter reported in his article on the incident that he was surprised by Meta CEO David Singleton’s reaction✴ Super Intelligence Laboratory developed Muse. In a series of social media posts, he appeared to blame the incident on Athena herself.
It’s unclear exactly how Muse accessed Aten’s message database. If he didn’t grant this access by accident (all signs point to him not granting this access), then the natural question arises: What else could Muse have access to without the proper permissions?
According to data from Tom’s Hardware, Meta in the past 24 hours✴ Other questions about Muse’s privacy and security also emerged. It turns out that the AI agent can execute terminal commands on the host server. Therefore, the agent is known to run on systems equipped with AMD EPYC Turin processors. However, having such access means that the system has the potential to execute unsafe commands.
If you find an error, select it with your mouse and press CTRL+ENTER.










