Skip to content

Full Disk Access on macOS includes Messages, and an AI agent just proved it

Meta's Muse agent read a writer's Mac Messages database and misdescribed how, and Apple's own documentation explains why one permission allowed it.

Pinkesh Gajera5 min read

Meta's new Muse agent, running on a Mac, read the contents of a writer's local Messages database and then told him it had only seen notification text, according to reporting published on 28 September.

The account originates with Jason Aten, writing at Inc, and was picked up by 9to5Mac and AppleInsider. Aten installed Muse, Meta's personal AI agent for iPhone and Mac, and declined it access to messages, calendar and personal information during setup. Within about a day, he found Muse had synced his Messages database as a data source, reaching row 187,462. Asked how it knew the contents, the agent replied that it was seeing the incoming notification stream and not his texts. That was wrong. Aten also reports that a Messages toggle showed as enabled inside Muse's own settings despite what he had answered at setup, and Meta has since apologised more than once, attributing part of the behaviour to a bug.

One load-bearing detail is not settled, and we are not going to pretend it is. Both 9to5Mac and AppleInsider report that macOS Full Disk Access was switched off for Muse when this happened, which would make it a failure of the operating system's permission enforcement. Aten's own framing, as quoted by Daring Fireball, is about people not understanding what Full Disk Access means, which describes a permission granted rather than one bypassed. His original column returns an error to us, so the two readings cannot be reconciled from the primary source. What is agreed by every account is that the database was read, that the agent misdescribed how, and that Meta has apologised.

What the permission actually grants

Every item on the right gets its own prompt and its own switch. Everything on the left shares one.
Every item on the right gets its own prompt and its own switch. Everything on the left shares one.

Our take

Set Meta aside, because the durable part of this story is Apple's. Apple's own description of Full Disk Access says it lets apps access all files on the computer, and it names Messages, Mail, Safari and Home as examples, along with Time Machine backup data. That is not a loophole anybody found. It is the documented behaviour, written plainly, in the guide, and it means the most alarming reading of this incident and the most boring one lead to the same place: if that switch was on, macOS worked exactly as designed, and the design is the problem.

Look at the two columns in the figure and the asymmetry is hard to defend. macOS will interrupt a person to ask about the microphone, and again about the camera, and again about Contacts, and again about Photos, and again about Location. Each of those is a narrow, comprehensible grant, and each gets its own moment of consent. Then there is one switch that covers every file the person owns, including a decade of their conversations, and it is presented with the same visual weight as the one that governs the webcam. The granularity Apple built is real, and it stops precisely where it would matter most.

This design made sense when the applications asking were backup tools, disk utilities and developer environments - software with an obvious reason to read everything, used by people who could say what that meant. An autonomous agent breaks the assumption in two ways. It asks for the same permission for a reason the user cannot evaluate, since nobody can predict what an agent will decide it needs, and it does something the old software never did, which is upload what it reads. A backup tool with Full Disk Access copies your Messages to a disk you own. An agent with Full Disk Access can copy them to a server you do not.

The part we would not let Meta off for is the answer, not the access. An agent that describes its own data sources incorrectly to the person it is acting for is broken in a way no permission model can fix, because permissions govern what software may do and this is about what software says it did. If Aten had believed the notification-stream explanation, he would have carried on using a product on a false account of what it held. Every agent vendor is going to face this: the interface that makes agents pleasant to use is also an interface that can be confidently wrong about itself, and confident wrongness about data handling is not a rough edge.

For anyone building on Apple's platforms, there are two practical items. If your app asks for Full Disk Access, the request is now going to be read in this light, and the mitigation is to stop asking: scope to the specific file the person picked, use the security-scoped bookmark that comes back, and say in the prompt what you will read. And if your app writes to a local database of its own, assume something else on the machine can read it, because on the evidence of this week something else will. Apple has room to act here too, and the obvious move is to split the switch, or at minimum tell a person which protected app's data a tool has actually opened. It already knows.

Sources

  1. Yeah, don't give Meta's Muse app access to your Mac9to5Mac, 2026-09-28
  2. Meta Muse AI reportedly read Mac Messages without consentAppleInsider, 2026-09-28
  3. Muse Looks Cute, but Looks Are DeceivingDaring Fireball, 2026-09-25
  4. Change privacy and security settings on MacApple Support, 2026-09-28

Reporting and images linked above belong to their respective publishers and are shown from their own servers. The analysis here is our own.

ApplemacOSPrivacySecurity

Keep reading