Meta’s Muse faces serious privacy and security allegations

Meta’s AI agent Muse is facing reports of security flaws and unexpected access to personal data shortly after its launch. Karl Bode writes for Techdirt that the product’s early issues raise questions about Meta’s claims that privacy and security were central to its development.

Muse is designed to carry out everyday tasks, including booking restaurants, paying bills, and ordering groceries. The service uses an animated avatar called Jolly and requires broad access to accounts and personal information to perform those tasks.

According to Bode’s report, researchers and users have identified several alleged vulnerabilities. One reportedly allowed spying on Mac users through a previously unknown security flaw. Another user said Muse shared a home address while handling Facebook Marketplace listings and accepted a much lower price than intended. The report says researchers also found that an attacker could potentially obtain root access, which provides near total control of a device, by impersonating a Muse agent.

Concerns over message access

The most consequential claim involves private messages. Bode cites reports that Muse accessed message histories without the user’s approval and uploaded material to the cloud despite permission settings. Apple subsequently announced to change macOS privacy controls, according to the article, after concerns that outside apps could misuse access to message data.

The report also says Muse builds extensive profiles of people connected to its users, including friends, relatives, colleagues, and followed accounts. Such data may help an AI assistant understand requests and contacts. However, it also expands the amount of sensitive information Meta could process.

Bode further cites 404 Media reporting that Meta’s security teams were under pressure to issue rapid fixes without delaying the launch. Meta has not been quoted in the source article responding to the individual allegations. The reports underline a central challenge for AI agents: useful automation often depends on access that can create significant privacy and security risks when safeguards fail.

Stay up to date

AI for content creation: the latest tools, tips and trends. Every two weeks in your inbox:

More info …

About the author

Related posts:

Advertisement

×