Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week

Meta's Muse Hit 3.4 Million Downloads in Its First 17 Days — Then Two Security Flaws Surfaced in One Week

Meta's Muse Hit 3.4 Million Downloads in Its First 17 Days — Then Two Security Flaws Surfaced in One Week

Sensor Tower estimates Meta's Muse agent passed 3.4 million downloads by September 25, days after topping the US App Store and Google Play free charts. The same week, researchers disclosed a bug-bounty flaw that could expose a user's Muse Secure VM and a macOS dictation hijack; Meta says it has shipped fixes and added clearer warnings.

Meta's Muse has been the fastest-consuming AI story of the month, and not only because of its adoption curve. The personal AI agent, launched on September 8, took the number one free-app spot on the US App Store by September 18 and on Google Play the next day. Sensor Tower estimated about 2.8 million downloads in its first two weeks, and TechCrunch reported the count had passed 3.4 million by September 25. But the same stretch produced two security disclosures that raise an uncomfortable question: what happens when an agent with sweeping permissions gets attacked?

Muse is not a chatbot. It sends email, books travel, shops and pays on a user's behalf, and keeps working after the app is closed. It runs Meta's Muse Spark model inside a per-user "Muse Secure VM" — an isolated cloud machine that holds whatever the agent needs to act: connected-account emails, files, credentials for shopping and travel.

The first flaw surfaced through Meta's bug bounty program. According to an internal incident report reviewed by The Information, an outside researcher found a way to access a user's dedicated VM — the very space where emails and files live. Meta initially classified the issue as SEV-2, its third-highest severity on a five-point scale, then downgraded it to SEV-3 after deciding the initial rating was wrong. The attack chain required a user to hand Muse a malicious link and then approve the resulting security prompt. Meta's fix is procedural as much as technical: warnings shown when Muse approaches a suspicious site are being made far more prominent.

The second disclosure came from macOS security researcher Patrick Wardle, who published a working proof-of-concept against the Mac app. An undocumented setting in Muse's local preferences — tied to its server-side voice dictation — could be flipped by any program already running in the user's account, redirecting dictation audio to an attacker's server and harvesting the authentication tokens behind it. From there, Wardle showed he could reach the VM credentials, read chats and invoke the agent itself, including remotely triggering actions on other devices under the same account, such as an iPhone. "Muse can do things that attackers basically can also do through Muse," he told reporters. Meta says it has shipped a hotfix that removes the setting entirely.

The two parties disagree on severity, and the disagreement is instructive. Meta frames the Wardle flaw as a local privilege escalation — malware must already be running on the Mac for any of it to work, making real-world risk low. Wardle's counterpoint is that the very thing that makes Muse useful makes it dangerous: an agent authorized to send email, spend money and control devices is a one-stop target, with a blast radius "far beyond what ordinary malware dreams of."

That tension is now the industry's core security problem. Consumer agents from Instinct, OpenAI and others are racing toward the same end-to-end authority, and every new connector or permission widens the attack surface. Meta's per-user VM design deserves some credit — a compromised session can be discarded without touching anyone else's data — but the disclosures show isolation alone is not a defense if the token that commands the VM can be stolen.

For users, the practical takeaway for now: install the hotfix, read the prompts before clicking approve, and treat an AI agent's credentials with the same care as a password manager's. The agent economy's convenience and its attack surface are, at least for the moment, the same feature.

Comments (0)

Log in to join the discussion

Log In

No comments yet