Muse logo

Autonomous agents

Muse

Meta's personal agent: browse, purchase, and act - shipped security-last

proprietary

Meta's consumer AI agent: answers questions, completes multi-step tasks, browses the web, makes purchases, generates images and documents, and connects to your apps. Free tier with usage limits. 12-day downloads beat ChatGPT's debut, then Patrick Wardle found a zero-day.

Meta’s personal AI agent launched to huge numbers (12-day downloads reportedly beat ChatGPT’s US/Canada debut; Meta stock rose 11 percent on launch-week Monday) and to a security failure on the same schedule. Capabilities: answer questions, complete tasks, browse the web, make purchases, generate images, create documents, and connect to apps through Connectors. It keeps working in the background after you close the app, asks permission before purchases and messages, and has a free usage tier with a paid upgrade. THE SECURITY INCIDENT (September 22, 2026): Mac security researcher Patrick Wardle found an undocumented configuration setting that controls which server handles dictation transcription. Any locally running application or terminal command could redirect that traffic to an attacker-controlled server, capturing voice prompts and the victim’s Muse account authentication token. Wardle’s proof-of-concept used the hijacked agent to take pictures and write files to disk, often without alerting the user; he called the result the ultimate backdoor. Meta issued a hotfix within a day and framed the practical risk as low because the exploit required prior local access. Wardle’s response: they should be thinking about security from the very start, and they are just not. Amazon separately blocked Muse from its e-commerce platform, saying Meta never obtained permission. The lesson for local-AI buyers: an agent with your permissions is only as safe as its network path, and a closed cloud agent does not let you audit that path.

The insight

The insight: an agent with your permissions is only as safe as its network path

The September 22 zero-day was not exotic: an undocumented setting pointed Muse’s dictation at whatever server the config named, and any local app could change it. The captured data was voice prompts and the account token - the keys to everything Muse touches: purchases, messages, files, camera. The lesson is not “Muse is bad,” it is that consumer agents concentrate permissions, and a closed product does not let you audit where your data actually goes. Meta patched within a day of publication, which is the full-disclosure argument working. If you run it, assume every connected app is exposed to whatever the agent can reach, and keep the permission prompts on allow-once.

In use

Muse screenshot: muse hero
muse hero

At a glance

Primary use case

Personal agent for everyday tasks, purchases, and connected-app actions

Founders

M

Meta

Source
closed-source
License
proprietary
Platforms
macOS, iOS, Android