Meta launched Muse on September 8, a personal AI assistant that can send emails, book travel, shop with saved payment methods, and act inside a person's calendar and files. Mark Zuckerberg described it as built from the ground up for privacy and security, and Meta backed that claim with a dedicated bug bounty of up to $300,000 for anyone who finds a serious flaw.
Less than two weeks later, a well known Mac security researcher, Patrick Wardle, found one anyway. He discovered that Muse's Mac app stores a setting that any program already running on the computer can edit, without needing a password or special permission. Changing that one setting lets an attacker reroute what a person says to their assistant to a server they control, and Wardle's demonstration showed the reach goes further than the Mac itself: a compromised computer was able to pull live location data and scan for nearby devices from an iPhone signed into the same Muse account.
The catch is that an attacker needs some way to run code on the victim's Mac first, so this is not a flaw that reaches out and grabs random strangers off the internet. But that bar is lower than it sounds. A lot of everyday malware, a bad browser extension, a pirated app, an infected download, already runs code on people's computers without them knowing. Once it does, Muse hands it a direct line into the assistant's access to a person's accounts and, through that, a linked phone.
This is Muse's fourth stumble in a month, not its first. Meta's own employees flagged security and reliability problems while testing the app in the days before launch. A tech columnist caught Muse pulling personal information from Mac notifications during a task, without ever disclosing that it was reading them. And on Sunday, Amazon began blocking Muse from shopping on its site, saying the agent never identified itself while browsing and appeared to store customer login details, something Amazon was not asked about beforehand.
None of this makes Muse unusual, and that is the real point. Every major tech company is racing to ship an assistant that can act on a person's behalf, and every one of them is running into the same wall: giving software the keys to someone's email, calendar, and wallet creates a target that did not exist when that software could only answer questions. Microsoft's Copilot had its own version of this problem earlier in the year, and Meta's predecessor model triggered a real security incident during closed testing months before Muse ever shipped.
The lesson for anyone outside the AI industry is simple. A company's own description of its security architecture is not evidence that architecture holds up, it is a claim waiting to be tested by outsiders. Muse is a consumer product, but the model behind it, an assistant with standing access to your accounts, is coming to workplace tools next. Wait for a few months of real-world scrutiny before connecting anything with financial or client data to an assistant this new, regardless of which company built it.