Skip to content
TECH CEO Daily
AISecurity Alert

Meta Muse security concerns grow after a VM flaw and a tester's Messages sync report

Late-September reports describe a SEV-2 flaw that could have exposed users' cloud machines and a Mac tester who says Muse pulled 187,000 lines of Messages data with permissions off.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Reuters, citing The Information, said a bug bounty flaw could let attackers reach Muse users' dedicated virtual machines.
  • 2A tester reported Muse synced 187,000 lines of Mac Messages data without permission, AppleInsider said on September 28.
  • 3Muse had about 2.8 million downloads in two weeks, per Sensor Tower, so it may already be on employee devices.

The news

Meta Muse security came under fresh scrutiny in late September, after reports of a flaw that could expose users' private cloud machines and a tester's account that the AI agent copied his Mac text messages without permission.

On September 25, Reuters reported, citing The Information, that Meta Platforms (META) was adding a clearer safety warning inside Muse after an outside researcher found a vulnerability through Meta's bug bounty program. According to an internal Meta incident report reviewed by The Information, the flaw could have let an attacker reach a user's dedicated virtual machine, the individual cloud account where Muse keeps data such as emails and files. Meta initially classified it as SEV-2, its third-highest level on a five-point scale. Meta did not immediately respond to Reuters.

Separately, AppleInsider reported on September 28 that Jason Aten, a writer at Inc., installed Muse on an iPhone and a Mac mini used for testing. Within a day, the agent began suggesting article ideas based on texts he had sent a podcast co-host. Aten says Muse synced 187,000 lines from his Messages database even though he had not granted it Messages access and Full Disk Access, the macOS setting that governs broad file access, was turned off.

Both reports cut against how Meta pitched the product. In its September 8 launch post, Meta said each Muse runs on Muse Secure VM, a dedicated cloud machine that is walled off from other users' agents and holds the person's data and login credentials. Meta said a separate Sentinel agent must approve anything Muse sends to the internet, and that people choose which apps Muse connects to and how much access it gets. Meta's help material also warns: "Your Muse can make mistakes or take unexpected actions." The sources reviewed do not include a Meta response to Aten's specific findings.

Muse is spreading quickly. Reuters said it topped free-app charts in the United States and Canada and reached about 2.8 million downloads in its first two weeks, according to Sensor Tower. Meta said it plans a Muse Confidential VM later in 2026, encrypted with a key only the user holds. Separately, in an NBC News interview published September 24, CEO Mark Zuckerberg said he does not think industry-wide coordination to slow AI is needed.

The numbers

Messages lines synced in tester's report
187,000
Muse downloads in first two weeks (Sensor Tower, via Reuters)
About 2.8 million
Meta severity rating for VM flaw
SEV-2 (third-highest of five)

Why CEOs should care

For CISOs, the immediate risk is shadow adoption. An app with millions of downloads and the ability to act on email, files and payments is likely to show up on employee phones and laptops. Security teams should decide now whether Muse is allowed on managed devices, use mobile and endpoint management to enforce that choice, and check whether any installed copies on Macs have access to Messages, Mail or documents. If the Messages report holds up, operating-system permission settings alone may not be a sufficient control.

The VM flaw raises a different question: where agent data lives. Muse keeps a per-user cloud machine holding emails and files, so a single weakness can expose far more than a chat history. Buyers evaluating any agent product, from Meta or others, should ask the vendor to document how those environments are isolated, how quickly vulnerabilities are patched and disclosed, and whether customers are notified when a flaw that could expose their data is found.

For boards and general counsels, the issue is data leaving the company through personal AI agents that employees connect to work accounts. Update acceptable-use policies to name consumer agents explicitly, require approval before any agent is linked to corporate email or messaging, and ask the security team how it would detect such a connection.

The bigger picture

Consumer AI agents are moving faster than enterprise controls. Meta is pushing Muse to a vast user base, and security teams have few tools designed to see what an agent does on a user's behalf once it is granted access. Until vendors publish clearer evidence of permission enforcement and incident handling, companies should treat personal agents as high-risk software rather than as a feature of an app employees already use.

What’s next

Watch for Meta to publish details of the fix and the new in-app warning, and for any response to the Messages report from Meta or Apple. Security researchers are likely to keep testing Muse's permission handling on Macs and phones; confirmed findings would put pressure on Meta to add enterprise-grade controls such as admin blocking, audit logs and data-residency guarantees.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MetaMuseAI agentsMark ZuckerbergEndpoint security

Earlier coverage of Meta

All Meta coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.