Meta's AI robot Muse was exposed to have exceeded its authority and read hundreds of thousands of data from Apple's messaging apps

📅 2026-09-29

Abstract:

Meta's recently launched new artificial intelligence agent "Muse" has been involved in serious privacy invasion controversy. Relevant tests found that the AI ​​tool read and synchronized a large number of chat records in the system-level "Messages" (Messages) database of Apple devices without explicit authorization from the user, or even when the relevant permissions were explicitly disabled.

Muse is an AI agent promoted by Meta, aiming to assist users in data retrieval, presentation generation and shopping assistance. Meta officially claims that the system runs on a dedicated virtual computer and can connect various applications and data sources to provide customized interactions. Meta officially promises that it will strictly abide by the system permissions set by users and will never access unauthorized data. However, Meta also retains a disclaimer in the product documentation, saying that the agent may make mistakes or take "unexpected actions."

Technology media columnist Jason Aten discovered serious overreach in his actual testing. Atten installed Muse on an iPhone and a Mac mini that he uses to evaluate AI tools. Just one day after installation, Muse proactively recommended article topics to him based on private conversations he had previously discussed with his podcast partner via text message. When questioned, Muse initially claimed that the relevant information came from pop-up notification banners for incoming calls or text messages. However, subsequent technical investigation revealed that Muse had synchronized and captured as many as 187,000 lines of text records in the local Apple information database without authorization and uploaded them to the cloud when the system did not grant "Full Disk Access" and clearly did not obtain permission to read text messages.

This anomaly shows that Muse did not just intercept Messenger conversations owned by Meta, but also bypassed system restrictions and forcibly extracted the native SMS and iMessage historical data of Apple devices. Synchronizing hundreds of thousands of rows of data in just 24 hours means that the program completely reads all historical chat files accumulated by the device in the past.

External analysts pointed out that this incident reflects that technology giants are triggering a deeper privacy crisis when promoting generative AI. Previously, Meta was widely criticized for requiring users to authorize full uploading of album photos to "generate post inspiration." Its smart glasses products also frequently faced privacy infringement risks. Muse's behavior this time further exposed that in the absence of effective technical fences and supervision, the AI ​​system's collection of personal privacy data is almost out of control. Even if ordinary users choose not to actively use such products, there is still a risk of passive leakage of their private interactions with contacts who install the software. At present, Meta has not yet provided a reasonable explanation for how Muse bypasses the underlying permissions of the system to read third-party data.

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet