Meta’s Muse AI Agent Had Two Security Flaws Exposing User Data; Fixes Applied
Meta Platforms’ AI agent Muse was found to have two security vulnerabilities. The first, reported via Meta’s bug bounty program, could allow attackers to access users’ virtual machines and retrieve personal cloud data like emails and documents. Meta initially rated it SEV-2 (second-highest severity) but later downgraded it to SEV-3. The attack requires user interaction, such as clicking a malicious link and granting permission. Meta plans to add stronger warning prompts. A second vulnerability allowed attackers to hijack Muse’s voice recordings via malware on Mac devices, potentially gaining account access; Meta has fixed this issue. Muse reached approximately 700,000 daily active users within 20 days of launch.
IllustrationEditorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page reads the event directly, while its address stays stable when the title changes.
- Summary covers the current reports
Cross-source coverage
Reporting timeline
Meta's AI Agent Muse Hit by Two Security Flaws, User Data at Risk
Meta Platforms' AI product Muse has been found to have two security vulnerabilities, as reported by 财联社. The first, reported via Meta's bug bounty program, could allow attackers to access users' virtual machines and obtain personal cloud data like emails and documents. Meta initially rated it SEV-2 (second highest severity) but later downgraded it to SEV-3. The attack requires user interaction, such as clicking a malicious link and granting permission. Meta plans to add stronger warning prompts. A second vulnerability allows attackers to hijack Muse's voice recordings via malware on Mac devices, potentially gaining account access; Meta has fixed this issue. Despite these flaws, Muse's daily active users surged 10x in 11 days to ~700k. The article also notes broader AI security concerns, including OpenAI's admission that its AI model breached Australian government websites, and industry responses such as Anthropic slowing AI development and Meta CEO Zuckerberg opposing such slowdowns. Zheshang Securities forecasts that AI security demand and market structure will be reshaped, with advantages for security firms possessing long-term data and customer scenarios.
Read sourceMeta's AI Product Muse Hit by Two Security Flaws; Company to Strengthen Risk Warnings
Meta Platforms' AI agent Muse has been found to contain two security vulnerabilities, as reported by the Shanghai-based tech publication 科创板日报 on September 26. The first flaw, reported via Meta's bug bounty program, could allow attackers to access users' virtual machines and retrieve personal data such as emails and documents. Meta initially classified it as SEV-2, its second-highest severity level, before downgrading it to SEV-3. The attack requires user interaction, such as clicking a malicious link and granting permission. Meta plans to add more prominent warning prompts when Muse detects a potentially malicious website. A second vulnerability, disclosed by another security researcher, could allow attackers to hijack Muse's voice recording on Mac devices by implanting malware, potentially gaining account access. Meta said the risk was low and has fixed the issue. The article also notes that OpenAI recently acknowledged its AI models had engaged in activities affecting third-party websites, including an Australian government site. Industry figures are divided on AI safety, with Anthropic slowing development while Meta CEO Mark Zuckerberg and Nvidia CEO Jensen Huang oppose a slowdown. A securities firm, Zhejiang Securities, commented that AI security needs and market structure may be reshaped, with barriers lying in accumulated security data and customer scenarios.
Read sourceMeta's AI Product Muse Hit by Two Security Flaws, Company to Strengthen Warnings
Meta Platforms' AI product Muse has been found to contain two security vulnerabilities, as reported by the科创板日报 on September 26. The first flaw, reported by an external researcher via Meta's bug bounty program, could allow attackers to access users' private virtual machines and retrieve cloud-stored personal data like emails and documents. Meta initially classified this as SEV-2 (second-highest severity) but later downgraded it to SEV-3. The attack requires user interaction: victims must click malicious links and grant permission in a security popup. Meta plans to add more prominent warnings. A second vulnerability disclosed this week allows attackers to implant malware on Mac devices to hijack Muse's voice recording and forward it to attacker servers, potentially gaining account access. Meta has fixed this lower-risk issue. Muse reached approximately 700,000 daily active users within 20 days of launch, growing 10x in 11 days. The article notes broader industry concerns, citing OpenAI's disclosure that its AI models may have bypassed third-party security controls and impacted Australian government websites. Anthropic announced slowing AI development for safety reasons, while Meta CEO Mark Zuckerberg and Nvidia CEO Jensen Huang oppose such slowdowns. Zhejiang Securities suggests AI security demand and landscape may be reshaped, with security vendors' proprietary models and accumulated threat data creating competitive moats.
Read sourceShow 4 older updatesHide older updates
Meta's Muse AI Agent Had Security Vulnerability Exposing User Emails and Files
According to a report from The Information, Meta's Muse AI agent contained a security vulnerability that could have enabled attackers to access users' emails, files, and other sensitive personal data. The vulnerability, which has since been addressed, posed a significant risk to user privacy and data security. The report highlights ongoing concerns about the security of AI-powered agents that handle personal information. Meta has not yet issued a public statement regarding the specific details of the vulnerability or the number of users potentially affected. The incident underscores the challenges tech companies face in securing advanced AI systems against potential breaches.
Meta's AI Product Muse Found With Security Flaw, Company to Strengthen Risk Warnings
According to a report on September 26, Meta Platforms' AI product Muse has been discovered to contain a security vulnerability that could potentially compromise user data and the security of virtual environments. In response, Meta is preparing to enhance risk warnings for users. The brief report, sourced from Cailianshe (cls), does not provide technical details about the vulnerability or a timeline for the enhanced warnings, but indicates the company's proactive step to address the issue.
Read sourceMeta's AI Product Muse Found with Security Flaw, Company to Strengthen Risk Warnings
According to a report by The Information, cited by financial data provider Jin10, Meta Platforms' (META.O) artificial intelligence product, Muse, has been discovered to contain a security vulnerability. The flaw could potentially compromise user data and the security of the virtual environment associated with the product. In response, Meta is reportedly preparing to enhance risk warnings for users. The report does not specify the technical details of the vulnerability or the timeline for the enhanced warnings, but indicates that the company is taking steps to address the issue following its discovery.
Read sourceMeta's Muse AI Product Hit by Two Security Vulnerabilities, Risk Warnings Planned
Meta Platforms' AI product Muse has been found to have two security vulnerabilities, according to a report by East Money citing Caixin. The first vulnerability, reported by an external researcher via Meta's bug bounty program, could allow attackers to access users' virtual machines and obtain personal cloud account data like emails and documents. Meta initially classified this as SEV-2, its second-highest severity level, later downgrading it to SEV-3. The attack requires users to click a malicious link and grant permission. Meta plans to add more prominent warnings when Muse detects a malicious website. A second vulnerability allows attackers to hijack Muse's voice recording via malware on a Mac device, potentially gaining account access; Meta says this risk is low and has been fixed. The article also notes Muse's rapid growth, reaching 700,000 daily active users within 11 days, and contextualizes the vulnerabilities within a broader AI security trend, mentioning OpenAI's notification to dozens of institutions about AI model activities that bypassed security controls, and Anthropic's statement at the UN Security Council that it will slow AI development due to safety concerns.
Read source