Exclusive: Meta Bolsters Muse Safety Warning After Security Vulnerability Found

Meta Platforms is adding a clearer safety warning within Muse after a security researcher discovered a vulnerability in the AI agent that could let an attacker access a user’s sensitive personal information.
The security flaw, which was flagged by an outside researcher through Meta’s bug bounty program and which hasn’t been previously reported, could have allowed an attacker to gain access to a user’s dedicated virtual machine, an individualized cloud-based account that contains data including emails and files, according to an internal Meta incident report that was seen by The Information. A Meta spokesperson said the vulnerability was initially misclassified as “SEV-2,” the company’s second-highest severity level on a five-point scale, which is typically reserved for incidents with significant impact. It was later reclassified as “SEV-3.”
The spokesperson said that for the attack to work a user would have to ask Muse to summarize or interact with a link to a malicious webpage and then click “allow” on a prompt that includes a safety warning. Meta is addressing the issue by making the warning message more prominent “as an extra layer of protection” if Muse suspects a user is connecting with a malicious website, the Meta spokesperson said.
Another security researcher this week reported a separate vulnerability in Muse that could enable an attacker to use malicious software injected onto a user’s Mac computer to redirect Muse’s voice recordings to the attacker’s server and gain access to the user’s account. A Meta official said earlier that the risk from that was low and that the company had fixed the issue.
Meta delayed Muse’s release for months to address privacy, security and user-trust concerns, though it acknowledged when it launched the agent earlier this month that Muse “isn’t immune to attack” and that security flaws where attackers try to trick AI agents remain an industry-wide problem.