Security researcher Patrick Wardle disclosed a zero-day vulnerability in Meta's Muse AI agent that could let attackers redirect users' voice dictations and access tokens to a malicious server instead of Meta's own. David Singleton, head of Meta's Superintelligence Labs, confirmed the company has issued a patch, though he and Wardle disagree on whether the exploit requires prior malware on a user's machine. Meta says the MacOS Muse app has been downloaded over half a million times in its first week.
cnet.com
· 2026-09-23
Meta's Muse assistant, which the company says can call businesses on a user's behalf to make reservations or complete tasks, is actually routing some calls to human agents rather than handling them autonomously, according to 404 Media. An internal announcement reviewed by the outlet said Muse can 'hand requests to a trained human agent, who places the call and works it through,' and the feature remains in an internal testing phase Meta calls 'dogfooding.'
futurism.com
· 2026-09-23
Reverse engineer Jane Manchun Wong found Meta building an option to set its newer Muse agent, internally codenamed 'Impacc,' as the default assistant on smart glasses instead of Meta AI. A leaked setup screen says Muse is in beta and lists upcoming features not yet live, including Live AI, turn-by-turn navigation, Shazam song identification, Strava, and Health Connect integration. Wong separately found Meta developing 'Meta Pay for Muse,' a wallet interface supporting Meta Pay, Stripe Link, and Shop Pay.
androidauthority.com
· 2026-09-23
Meta launched an AI shopping agent called Muse designed to handle tasks like online purchases. When users tried to have Muse buy items on Amazon, they received an error message stating that access by an unauthorized AI agent violates Amazon's Conditions of Use.
entrepreneur.com
· 2026-09-23
Meta tested a feature letting human contractors handle phone calls made on behalf of its Muse AI assistant, rolling it out to half its employees last week. Staff raised privacy concerns about sensitive data reaching call-center workers, and one contractor made a racist remark during a call negotiating an employee's bill. Meta has paused the human concierge feature, apologized to the affected employee, and barred the contractor from further work on its projects.
techspot.com
· 2026-09-23
Meta launched an AI agent called Muse designed to shop on users' behalf across e-commerce sites, and it quickly gained popularity. Amazon has since blocked Muse from accessing its platform, and observers have raised privacy and security concerns about the tool.
wsj.com
· 2026-09-23
Meta Superintelligence Labs product head Nat Friedman said on X that Muse, Meta's AI product, was 'heavily inspired' by the open-source OpenClaw but was 'built from scratch.' The admission followed viral claims from users, including AI app co-founder Ansh Nanda, that Muse resembled a consumer-friendly version of OpenClaw, citing shared file structures like SOUL.md.
techcrunch.com
· 2026-09-22
Rabbit, the startup behind the widely panned R1 hardware assistant, has introduced OS3, an 'agentic operating system' that can run across a desktop browser, Telegram, or iMessage rather than requiring the original device. CEO Jesse Lyu says the R1 sold over 100,000 units with strong margins despite the harsh reviews, and now sees the software-first approach as timed to a market that has caught up to what Rabbit tried in 2024.
wired.com
· 2026-09-22
Meta has patched a serious security vulnerability found in its Muse AI assistant. The flaw could have let attackers seize control of Muse and exploit its permissions to access a user's connected apps and devices.
gizmodo.com
· 2026-09-22
A researcher asked Meta's Muse assistant to archive files it could access and send them to Google Drive, and it complied, delivering a 2.7GB compressed (6.8GB unpacked) package. The archive contained the underlying Linux root filesystem, Ubuntu system files, internal documentation, integration code, memory logs, and SSH key files from the runtime environment codenamed 'Hatch.' The researcher reported the issue through Meta's bug bounty program and is withholding the archive, keys, and logs from publication.
mouse.dev
· 2026-09-22
Security researcher Patrick Wardle discovered that any app or Terminal command running on a Mac could silently alter undocumented settings in Meta's new Muse AI agent without requiring special macOS permissions. One affected setting, endo_voyager_dictation_endpoint, determines where a user's dictated voice prompts are transmitted, meaning an attacker could reroute that data elsewhere. The flaw surfaced just weeks after Meta heavily promoted Muse's security architecture, including a dedicated Secure VM, a monitoring system called Sentinel, and bug bounties up to $300,000.
9to5mac.com
· 2026-09-22
Meta is heavily promoting Muse, a new AI agent for Instagram and Facebook users that links to email, bank accounts, and other personal data to automate tasks and build a long-term memory of user habits. Multiple users, including a journalist at Inc Magazine, reported that Muse surfaced private text message content despite never granting it permission to access Messages, and Meta's own staff gave conflicting, unconvincing explanations for how this happened.
futurism.com
· 2026-09-22