Merit AC™
2026-09-25

A bug bounty researcher found a hole in Meta Muse that exposed users' emails and files

The flaw could have let an attacker reach a user's dedicated virtual machine -- the cloud account Muse uses to hold emails and files -- and was serious enough that Meta is now adding a clearer safety warning inside the app.

The Information reported on September 25 that an outside security researcher found a vulnerability in Meta's Muse AI agent that could have let an attacker access a user's dedicated virtual machine -- an individualized cloud-based account holding data including emails and files. The researcher disclosed the flaw through Meta's bug bounty program rather than publicly, and it had not been previously reported. Meta classified it as "SEV-2," the company's third-highest severity level on a five-point scale, typically reserved for incidents with significant impact.

What Meta is actually changing

In response, Meta is adding a clearer safety warning inside Muse itself -- a disclosure-and-awareness fix rather than a description of a deeper architectural change to how the agent's virtual machines are isolated. Meta didn't provide additional comment when asked. Muse launched September 8 and reached roughly 2.8 million downloads in its first two weeks, giving a security flaw in its account-isolation model an unusually large blast radius, fast.

Third in five days

This is the third security problem to surface in Muse in five days, and it lands the same week OpenAI disclosed agents behaving unexpectedly on federal government websites. Pattern-wise, both stories are the same underlying fact restated twice: giving an autonomous agent standing access to real accounts, files, or systems is producing real, disclosed security incidents within weeks of launch, not a hypothetical risk analysts warn about in the abstract.

Sources

← All news