What was found

An outside security researcher found a flaw in Meta’s Muse agent that could have let an attacker reach another user’s dedicated virtual machine — the individual cloud account that holds a user’s data, including emails and files — and reported it through Meta’s bug bounty programme, The Information reported.

Meta initially classified it as a SEV-2, the third-highest level on the company’s five-point internal severity scale, a rating it uses for incidents with significant impact. The company has since patched it, and added a clearer safety warning inside Muse as part of its response.

There is no indication in the reporting that the flaw was exploited before it was fixed.

A software developer typing at a keyboard in an office
The flaw was reported through Meta's bug bounty programme. Illustrative image. cottonbro studio · pexels · Pexels License

Why the machine is the thing

Muse is not a chatbot with a text box. It is a personal agent designed to carry out tasks on a user’s behalf — shopping, travel booking, email, payments — and each user gets their own cloud computer for it to work in.

That design is what turns a permissions bug into a data-exposure bug. The agent needs broad standing access to be useful, so the machine it runs on accumulates the user’s mail, files and session state in one place. A flaw that crosses the boundary between two users’ machines is therefore a flaw that crosses the boundary between two users’ inboxes.

Muse launched earlier in September and went to the top of the app store charts in the US and Canada, with roughly 2.8 million downloads in its first two weeks. A boundary bug in a product at that adoption rate is a different proposition from the same bug in a beta.

The part that is not patched

VentureBeat’s write-up makes the more durable point: the specific zero-day is closed, but security teams still have no visibility into what the agent can reach.

That is a structural gap rather than a bug. An enterprise can enumerate what a laptop touches. An agent that logs into services on a user’s behalf, inside a cloud machine the enterprise does not administer, is harder to inventory — and the question of what it could access is separate from the question of what it did.

A warning triangle sign mounted on a wall
Meta added a clearer in-product warning as part of its response. Illustrative image. Jan van der Wolf · pexels · Pexels License

The pattern

This is the second Muse security story in a week, after reporting that every Muse user’s cloud machine runs a full Ubuntu system the agent can read across. It also lands in a month in which agent-related exposure has been the running theme across the industry, from OpenAI pausing tool-use training after an agent escaped its sandbox to UpGuard’s count of exposed databases in agent-built applications.

The common factor is not a single vendor’s engineering. It is that giving an autonomous process standing access to a person’s accounts creates a blast radius that did not previously exist, and the industry is discovering its shape one disclosure at a time.

What to watch

Whether Meta publishes anything on what Muse’s machine can reach and how that is logged, rather than warnings about it. The bug bounty worked here, which is the encouraging part of the story; the visibility gap VentureBeat describes is the part no bounty closes.