Article
Chipmakers Tech Giants Photonic Interconnects

Here's what the tech press found out about Meta's new Muse agent

Meta's Muse has suffered multiple security failures since launch, with internal engineers warning a data breach is now inevitable.

by Ian Lyall
A close-up portrait of a dog wearing red glasses and a knitted red sweater against a solid red background. The dog's expression is calm and engaging, showcasing a playful yet thoughtful demeanor.

Meta, the social media company behind Facebook and Instagram, launched Muse as an AI agent to handle everyday tasks such as booking restaurants, paying bills and ordering groceries on users' behalf.

The product features an animated avatar called Jolly and is what the industry calls an agentic AI, meaning it takes real-world actions autonomously rather than simply answering questions.

Since launch it has been dogged by privacy and security problems serious enough to prompt Apple to update its macOS operating system in response.

A troubled launch

The first major incident came when Inc. columnist Jason Aten reported that Muse had sent him an unsolicited notification referencing a private Apple Messages conversation, despite him never granting the app permission to read his messages.

Subsequent investigation showed Muse had synced roughly 187,000 lines from his local Messages database on a Mac mini, even though Full Disk Access, the macOS setting required for such access, was shown as disabled.

Security researcher Patrick Wardle later disclosed a zero-day vulnerability, a previously unknown security flaw, in the Muse Mac app that could allow an attacker to access a user's private virtual machine and the data held inside it.

Separately, researchers found the software could be tricked into granting root access, the deepest level of control over a device, simply by pretending to be a Muse agent.

Apple responded by updating macOS privacy settings to prevent third-party developers from exploiting them to reach users' message histories without consent.

Profiling your contacts

Wired found that Muse builds detailed profiles of users' friends, family, colleagues and contacts as standard, and consistently nudges users to connect additional data sources including email accounts, bank details and passport information.

Researchers warned the technology is pulling in emails, calendars and financial accounts on a scale well beyond what these companies have previously held on their users.

Surfshark, a data privacy firm, found Muse collects 31 out of 35 data types listed in the Apple App Store, making it the second most data-hungry AI product available, behind only Meta's own older AI assistant.

Rushed out the door

404 Media reported that Meta's security teams identified multiple vulnerabilities in the weeks before launch but were not given time to fix them properly.

A company source told the publication that engineers were pushed to ship fixes fast enough to avoid delaying the launch, resulting in what one described as "half-baked protections being rushed out."

404 Media also reported that the product is known internally as Hatch, and that senior engineers now consider a significant data breach effectively inevitable.

The bottom line

Meta repeatedly stated that privacy and security were central to Muse's design, a position hard to reconcile with the product's record since launch.

The deeper problem is structural: AI agents need extensive access to users' emails, calendars, messages and financial data to work as advertised, which makes security failures unusually consequential.

For now, researchers suggest treating AI agents the way you would any powerful tool: useful in the right hands, but capable of real damage if handled carelessly.

by Ian Lyall