Apple changes macOS privacy settings to block misuse of message access

Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories. The announcement came on a Friday, two weeks after tech columnist Jason Aten said that Meta's new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages.
Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media blew up the following week with people who agreed with him. They said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts and other resources are akin to a skill saw or other power tool: potentially useful, but able to do real damage if not used carefully.
Meta CTO David Singleton rebutted Aten's account, and the article describes the rebuttal as one that appeared solid. According to Singleton, for Muse to access Apple Messages a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse. "The Messages integration in the Muse Mac app is opt in," Singleton said. "Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled." The article author reads the implication as clear: Muse could have read Aten's messages only if he had enabled both settings, in which case the columnist had only himself, and not Meta, to blame.
The author then spoke to macOS security expert Patrick Wardle, who questioned Singleton's denial. Wardle's reasoning: "From a technical point of view, with FDA (full-disk access), any (non-root file), is readable, browsing history, browser cookies, chats, etc etc etc." The author also asked Meta how Muse couldn't read messages when the app had full disk access, while every other app with that privilege could. Meta PR's only response was to requote Singleton's statement that the integration is opt-in and that Muse can only read Messages content if both Full Disk Access and the Messages connector are enabled.
Key facts
- Apple says it is changing macOS privacy settings to stop third-party app developers from misusing them to access message histories.
- The announcement came two weeks after columnist Jason Aten said Meta's AI agent Muse sent him a notification referencing a thread with a co-worker over Apple Messages.
- Meta CTO David Singleton said Muse can read Messages only if the user grants macOS Full Disk Access and enables the Messages connector in Muse.
- Security expert Patrick Wardle questioned the denial, noting that with full-disk access any non-root file is readable, including browsing history, cookies and chats.
- Asked how Muse couldn't read messages with full disk access when other apps with that privilege could, Meta PR only requoted Singleton.
Why it matters
AI agents are being given access to calendars, emails, messages and shopping accounts, and this episode shows how quickly that access becomes a privacy argument. Apple's decision to change its macOS privacy settings is a platform-level response to concerns about apps reaching message histories. Commenters framed such assistants as power tools that can do real damage if not used carefully.
Who it affects
Mac users who run third-party apps, especially AI agents that ask for full-disk access. Developers of such apps are the ones Apple says it wants to stop from misusing the privacy settings. Meta, whose Muse agent has a Mac app, is at the centre of the dispute that preceded the announcement.
How to use it
The source gives no steps for users. It does describe the two settings Singleton says must both be on for Muse to read Apple Messages: macOS Full Disk Access, and the Messages connector in the Muse app. Checking both on a Mac that runs Muse is the practical takeaway.
How solid is it
Apple's announcement is reported by the article, but the crawled text does not say what exactly Apple is changing in full-disk access or macOS privacy settings, or in which macOS version or when it takes effect. The Muse episode itself is contested: Aten says he never granted permissions, Singleton says two opt-in settings are required, and the text does not say whether Muse actually read Aten's messages. Wardle's quote is about what full-disk access permits in general, not a statement that Muse read the messages.
Risks and caveats
The dispute is unresolved in the available text, so it would be wrong to treat either Aten's account or Meta's rebuttal as established. The text also does not say that Apple named Meta or Muse in its announcement. Full-disk access, in Wardle's description, exposes any non-root file, which is why granting it to any app carries wide consequences.
“Your Muse can only read Messages content if macOS system-level Full Disk Access is granted and the Messages connector is enabled.”
— David Singleton, Meta CTO