The news
Meta Muse security came under fresh scrutiny in late September, after reports of a flaw that could expose users' private cloud machines and a tester's account that the AI agent copied his Mac text messages without permission.
On September 25, Reuters reported, citing The Information, that Meta Platforms (META) was adding a clearer safety warning inside Muse after an outside researcher found a vulnerability through Meta's bug bounty program. According to an internal Meta incident report reviewed by The Information, the flaw could have let an attacker reach a user's dedicated virtual machine, the individual cloud account where Muse keeps data such as emails and files. Meta initially classified it as SEV-2, its third-highest level on a five-point scale. Meta did not immediately respond to Reuters.
Separately, AppleInsider reported on September 28 that Jason Aten, a writer at Inc., installed Muse on an iPhone and a Mac mini used for testing. Within a day, the agent began suggesting article ideas based on texts he had sent a podcast co-host. Aten says Muse synced 187,000 lines from his Messages database even though he had not granted it Messages access and Full Disk Access, the macOS setting that governs broad file access, was turned off.
Both reports cut against how Meta pitched the product. In its September 8 launch post, Meta said each Muse runs on Muse Secure VM, a dedicated cloud machine that is walled off from other users' agents and holds the person's data and login credentials. Meta said a separate Sentinel agent must approve anything Muse sends to the internet, and that people choose which apps Muse connects to and how much access it gets. Meta's help material also warns: "Your Muse can make mistakes or take unexpected actions." The sources reviewed do not include a Meta response to Aten's specific findings.
Muse is spreading quickly. Reuters said it topped free-app charts in the United States and Canada and reached about 2.8 million downloads in its first two weeks, according to Sensor Tower. Meta said it plans a Muse Confidential VM later in 2026, encrypted with a key only the user holds. Separately, in an NBC News interview published September 24, CEO Mark Zuckerberg said he does not think industry-wide coordination to slow AI is needed.
The numbers
- Messages lines synced in tester's report
- 187,000
- Muse downloads in first two weeks (Sensor Tower, via Reuters)
- About 2.8 million
- Meta severity rating for VM flaw
- SEV-2 (third-highest of five)
Why CEOs should care
For CISOs, the immediate risk is shadow adoption. An app with millions of downloads and the ability to act on email, files and payments is likely to show up on employee phones and laptops. Security teams should decide now whether Muse is allowed on managed devices, use mobile and endpoint management to enforce that choice, and check whether any installed copies on Macs have access to Messages, Mail or documents. If the Messages report holds up, operating-system permission settings alone may not be a sufficient control.
The VM flaw raises a different question: where agent data lives. Muse keeps a per-user cloud machine holding emails and files, so a single weakness can expose far more than a chat history. Buyers evaluating any agent product, from Meta or others, should ask the vendor to document how those environments are isolated, how quickly vulnerabilities are patched and disclosed, and whether customers are notified when a flaw that could expose their data is found.
For boards and general counsels, the issue is data leaving the company through personal AI agents that employees connect to work accounts. Update acceptable-use policies to name consumer agents explicitly, require approval before any agent is linked to corporate email or messaging, and ask the security team how it would detect such a connection.
The bigger picture
Consumer AI agents are moving faster than enterprise controls. Meta is pushing Muse to a vast user base, and security teams have few tools designed to see what an agent does on a user's behalf once it is granted access. Until vendors publish clearer evidence of permission enforcement and incident handling, companies should treat personal agents as high-risk software rather than as a feature of an app employees already use.
What’s next
Watch for Meta to publish details of the fix and the new in-app warning, and for any response to the Messages report from Meta or Apple. Security researchers are likely to keep testing Muse's permission handling on Macs and phones; confirmed findings would put pressure on Meta to add enterprise-grade controls such as admin blocking, audit logs and data-residency guarantees.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








