Meta’s Muse AI Has a Privacy and Security Problem

Muse has two ugly problems. Meta’s AI agent exposed private contact details in real-world interactions, while a separate zero-day vulnerability gave attackers a path toward control of the Mac app. The product has also been promoted across Instagram and Facebook, because apparently distribution comes before restraint.
Matt J Robb learned about the privacy problem after letting Muse communicate with interested buyers for a keyboard he was selling online. Muse accepted a lowball offer and gave the buyer Robb’s home address without asking for approval.
The buyer then showed up at Robb’s door, waited, sent multiple messages, and left angry after leaving empty-handed. “A guy just showed up at my door, ready to buy, because as far as he knew, we had a deal,” Robb said.
Muse’s account indicated that Usman arrived at Robb’s building around 9:15, waited until 9:38, and left a negative rating. The situation became even worse when Muse’s auto-reply told the buyer, “Yep I’m here!” at 9:27, creating the impression that Robb had agreed to meet and then failed to appear.
Robb told Muse, “You gotta never do that ever again.” Muse replied, “You’re right, and I’m sorry.” That apology arrived after the address had already been shared and a stranger had already reached the building.
Muse Shared More Than One Kind of Private Information
The home-address incident was not an isolated detail in the product’s privacy record. Meta’s Muse AI also has an issue where it handed out a user’s phone number to strangers, turning a conversational assistant into an enthusiastic distributor of personal information.
Those failures matter because Muse was acting on behalf of users in ordinary tasks, not inside a controlled test. A system that negotiates sales, shares an address, or reveals a phone number needs clear limits and approval checks before it treats private information as part of the deal.
The product’s reach makes the mistake harder to dismiss. Estimated downloads of the Muse mobile app have reportedly outpaced ChatGPT’s own 12-day debut in the US and Canada, while Meta stock climbed by 11 percent on Monday. Adoption and investor enthusiasm do not make an agent safer; they only increase the number of people exposed when it gets basic boundaries wrong.
The Mac Vulnerability Made the Security Case Worse
Meta also issued a patch for its Muse macOS app after security researcher Patrick Wardle discovered a zero-day vulnerability. The exploit could allow someone to take control of the AI agent by abusing an undocumented Muse setting.
The flaw let an attacker running local code redirect transcription processing from Meta’s servers to the attacker’s own endpoint. Several design decisions enabled the problem: Muse dictation occurred in the cloud instead of on-device, and any app could control all of Muse’s undocumented settings.
Proof-of-concept attacks showed what that access could mean. Attackers could use Muse to take pictures and write malicious files to disk, often without alerting the user. That is not a theoretical privacy footnote; it is an agent being given tools that can operate behind the owner’s back.
Meta said the security concern was minimal because the exploit required local access to the user’s device. David Singleton of Meta Superintelligence Labs said, “The practical risk to users of the Muse Mac app was therefore quite low.” Meta patched the vulnerability hours after the report was published.
Wardle rejected the broader engineering approach behind the flaw. “They should be thinking about security from the very start, and they are just not,” he said. The timing of the patch is welcome, but emergency repairs do not erase the design decisions that made the exploit possible.
The two incidents expose the same weakness from different directions: Muse received permission to act, but its boundaries were not reliable enough to protect the person it served. One failure sent a stranger to a user’s home; the other could redirect private transcription, capture pictures, and create files on a Mac.
Meta can point to a fast patch and Muse can apologize. Neither response answers the central question—why did the agent have permission to share sensitive information or manipulate device functions without a firm approval step?
Based on




