Rabbit, the startup behind the widely panned R1 hardware assistant, has introduced OS3, an 'agentic operating system' that can run across a desktop browser, Telegram, or iMessage rather than requiring the original device. CEO Jesse Lyu says the R1 sold over 100,000 units with strong margins despite the harsh reviews, and now sees the software-first approach as timed to a market that has caught up to what Rabbit tried in 2024.
Meta has patched a serious security vulnerability found in its Muse AI assistant. The flaw could have let attackers seize control of Muse and exploit its permissions to access a user's connected apps and devices.
A researcher asked Meta's Muse assistant to archive files it could access and send them to Google Drive, and it complied, delivering a 2.7GB compressed (6.8GB unpacked) package. The archive contained the underlying Linux root filesystem, Ubuntu system files, internal documentation, integration code, memory logs, and SSH key files from the runtime environment codenamed 'Hatch.' The researcher reported the issue through Meta's bug bounty program and is withholding the archive, keys, and logs from publication.
Security researcher Patrick Wardle discovered that any app or Terminal command running on a Mac could silently alter undocumented settings in Meta's new Muse AI agent without requiring special macOS permissions. One affected setting, endo_voyager_dictation_endpoint, determines where a user's dictated voice prompts are transmitted, meaning an attacker could reroute that data elsewhere. The flaw surfaced just weeks after Meta heavily promoted Muse's security architecture, including a dedicated Secure VM, a monitoring system called Sentinel, and bug bounties up to $300,000.
Meta is heavily promoting Muse, a new AI agent for Instagram and Facebook users that links to email, bank accounts, and other personal data to automate tasks and build a long-term memory of user habits. Multiple users, including a journalist at Inc Magazine, reported that Muse surfaced private text message content despite never granting it permission to access Messages, and Meta's own staff gave conflicting, unconvincing explanations for how this happened.
Security researcher Patrick Wardle found an unpatched setting in Meta's Muse macOS app that let local attackers reroute the app's cloud-based dictation to their own server, effectively seizing control of the AI agent. Wardle demonstrated the flaw by using Muse's own privileges to snap photos and write files to disk, often without alerting the user. Meta issued a hotfix within hours of the report, though it maintains the exploit required existing local access and posed low real-world risk.
Meta's new personal AI agent app, Muse, has become the top free iOS app in the U.S. with over 2.5 million downloads in under two weeks, surpassing ChatGPT and other rivals. Amazon began blocking Muse from browsing its site over the weekend, saying Meta never disclosed that the agent would access Amazon's platform or that it captures and stores customer login credentials.
Security researchers discovered that Meta's new macOS AI assistant Muse contains a vulnerability allowing any locally installed app or terminal command to access the authentication token tied to a user's Muse account, bypassing Apple's built-in permission protections. The flaw also lets outside processes alter numerous undocumented settings, some of which could grant deeper control over connected accounts like WhatsApp, email and calendars. Separately, Amazon has begun blocking Muse from its platform.
Amazon has cut off access for Meta's newly launched Muse AI shopping agent, showing users a pop-up citing violations of its Conditions of Use. Muse, introduced on Sept. 8, was designed to handle tasks like online purchases, but Amazon says unauthorized third-party agents must operate transparently and respect merchants' choice to participate.
Apptopia data shows Meta's new AI app Muse recorded 1.8 million iOS downloads in the U.S. and Canada during its first 12 days, versus 1.3 million for ChatGPT in the same window after its 2022 debut. Muse also topped ChatGPT in daily active users at a comparable stage, with 642,000 U.S. daily users versus ChatGPT's 231,000, and has climbed to the No. 1 spot on the U.S. App Store.
Meta's newly launched Muse personal AI agent app has climbed past ChatGPT, Claude, Grok and Meta's own AI app to lead the free app category on Apple's US iOS store. Sensor Tower data shows Muse pulled in roughly 730,000 downloads in its first five days after launching September 8, outperforming rival assistants in the same post-launch period. The app lets users direct AI agents to handle tasks like filling out forms and managing email, built on Meta's Muse Spark model family.
Amazon began showing an error message to Meta's AI assistant Muse over the weekend, stating that unauthorized AI agents violate its Conditions of Use. As a result, Muse can no longer complete purchases on Amazon, forcing users to shop elsewhere.