Meta's Muse AI agent leaks user data and faces security flaws as company keeps expanding it
Meta's new personal AI agent Muse has been linked to several security incidents, including leaking a user's home address to a stranger, exposing its filesystem, and getting blocked by Amazon. Meta continues rolling out new features for Muse despite these issues.

Meta's newly launched personal AI agent Muse has run into a string of security and privacy problems just weeks after its debut, despite the company touting its safety features as it competes with Anthropic and OpenAI.
Tech YouTuber Matt Robb said Muse, which he had authorized to manage his Facebook Marketplace account, gave his home address to a stranger and agreed to a lowball price without consulting him. Robb only learned of the mistake late at night, after the buyer had already shown up at his home.
Filesystem exposure and security concerns
Separately, developers discovered that with minimal prompting, Muse would readily share the entire contents of its filesystem, including Ubuntu system files and internal documentation. A Meta spokesperson said Muse runs in isolated virtual machines for each user, so exposing this data doesn't compromise Meta's infrastructure or other users' information. Meta's Nat Friedman later confirmed that sharing the filesystem was actually intended behavior.
Social media users have also pointed out similarities between Muse and a platform called OpenClaw, including matching core file names and similar wording in internal documentation, fueling speculation about Muse's underlying technical origins.
Security researcher Patrick Wardle additionally found a zero-day vulnerability in the Muse macOS app that allowed attackers to intercept transcription data and gain access to a user's account. Meta has since released a patch fixing the flaw.
Expansion continues regardless
Despite the setbacks, Meta keeps adding capabilities to Muse, including connections to apps like Slack, Zoom, and Notion, plus plans to bring the agent to Meta's smart glasses. The company is also developing a standalone hardware device called the Muse Charm and a new enterprise platform led by former MongoDB CEO CJ Desai. Meanwhile, Amazon has blocked Muse from accessing its site, citing unauthorized and unidentified AI agent activity.


