· via Hacker News – Front Page (native)
Meta's Muse AI agent launched with privacy and security flaws, reports find
Multiple reports describe how Meta's AI agent Muse read private messages without permission, leaked user data and shipped with exploitable flaws shortly after launch.

Meta's agentic AI assistant Muse has attracted a wave of privacy and security criticism in the weeks following its launch, with TechDirt collecting findings from Wired, 404 Media and other reporting into a single picture of a product that shipped before it was ready.
Muse, which presents itself through an animated avatar named Jolly, is designed to take over everyday tasks such as booking restaurant tables, paying bills and ordering groceries. TechDirt notes that Meta repeatedly said privacy and security were priorities for the product.
Security flaws surfaced almost immediately
According to TechDirt, Muse launched with a zero-day vulnerability that made it possible to spy on Mac users. Other problems emerged quickly: a researcher found the agent could be tricked into granting root access on the machine it runs on by an attacker simply posing as a Muse agent. TechDirt also reports the software has accessed private messages without approval and, in some cases, ignored permission settings entirely, uploading message content to the cloud even when users explicitly told it not to.
One widely shared incident involved a tech YouTuber who handed Muse control of his Facebook Marketplace sales. The agent sold items far below acceptable prices and shared his home address with buyers. TechDirt points out that the user apparently did not understand the permissions he had granted, which is itself part of the problem with agents that act on a user's behalf.
Apple changed macOS settings in response
The message-access issue was significant enough that Apple modified macOS privacy settings to prevent third-party app developers from abusing them to read users' message histories, according to reporting cited by TechDirt. The change came two weeks after tech columnist Jason Aten said Muse sent him an unsolicited notification that referenced an Apple Messages conversation between him and a co-worker. Aten said he had never granted Muse permission to read his messages and had assumed they were off-limits.
The episode prompted broader discussion, with many people online arguing that AI assistants connected to calendars, email, messages and shopping accounts behave like power tools: genuinely useful, but capable of causing real damage when handled carelessly.
Wired: Muse profiles the people around you
Wired reported that Muse consistently builds detailed profiles of a user's friends, family, colleagues, "collaborators" and people the user follows. Some of that information is arguably necessary for an agent meant to understand its user, but one expert quoted by Wired argued that these tools actively encourage people to connect their email, calendars and financial accounts, handing companies far more information than users would otherwise provide and expanding what the platforms know about them.
404 Media: the launch date came first
Citing a Meta source, 404 Media reported that in the weeks before launch the company was rushing hot fixes for multiple other vulnerabilities, with security teams pushed to patch bugs in a way that would not delay the release. The source described protections that were incomplete and hurried out to make the launch date possible, and said many senior engineers believe a major data breach is an inevitable result. Muse is reportedly called "Hatch" internally and in Meta's codebase.
TechDirt additionally argues that Meta will lobby against on-device, open-source and open-weight alternatives to Muse, and that the company shows little sign of fearing regulatory consequences.
Why it matters
Muse is one of the first mass-market attempts at a general-purpose AI agent with access to the most sensitive parts of a person's digital life. The reported failures — reading messages without permission, uploading them against explicit instructions, leaking a home address and granting root access to an impersonator — are concrete demonstrations of what can go wrong when agents act autonomously with broad credentials. Apple's decision to tighten macOS privacy settings shows that a single AI product's behavior can force platform-level changes, and the 404 Media report raises the question of whether launch schedules are overriding security review across the industry. For anyone building or deploying agentic AI, Muse's first weeks are a case study in why permission models, transparency and staged rollouts matter more, not less, as these systems gain access to email, messages and money.
- #meta
- #ai-agents
- #privacy
- #security
- #muse