I refused to install Meta Muse after finding 4 critical security flaws that Meta won't acknowledge

While the term "agentic AI" has circulated in tech and business for some time, frontier AI companies like OpenAI and Meta are now reimagining it for the masses.Imagine an AI pet with a cute name and a distinctive personality that can perform tasks on your behalf.That's essentially the idea behind OpenAI's Dots and Meta's Muse — personal AI agents designed to handle tasks for you.

When my editor assigned Meta Muse to my assignment queue, the directive seemed straightforward: install the app, link my emails and data, and see if Jolly — Meta's cartoon mascot — could actually streamline my daily workflow.But when I started researching the app beforehand, I found several critical red flags, including handing over sensitive data to Meta, Muse falsely handling a Facebook Marketplace negotiation on a user's behalf, reading private texts without explicit permission, and more.This prompted me to write this instead of a typical tips-and-tricks guide to Meta Muse.

Muse turns Meta into a high-risk credential broker You're essentially handing all critical login data to Meta Close For Meta Muse to log in to your favorite shopping sites or platforms and act on your behalf, it needs to store your credentials and authenticate with those services.While modern web agents rely on scoped OAuth tokens and explicit API integrations to communicate with third-party services, Muse relies on broad service connectors and browser automation, asking users to store their credentials in Meta's proprietary Secure Credentials Store.Meta claims it has a secure workflow for these credentials and says the agent cannot read them, but I don't buy it.

I'm not comfortable giving Meta access to all my accounts.I keep my digital accounts' credentials isolated behind a dedicated, zero-knowledge password manager like Bitwarden, where master keys never leave my local storage unencrypted.Some demos of Meta Muse online indicate the app will require full disk access and connect to your email, calendar, Instagram, and other apps, depending on the connector you enable.

Granting a Meta AI agent "full disk access" feels particularly alarming to me.It silently synced 187,000 private text messages Why you can't trust what Meta's agent tells you about your privacy We rely on system-level permissions as an ultimate boundary between our local data and third-party services like Muse.But Meta Muse appears to put that boundary in jeopardy.

A recent report from columnist Jason Aten claims that his Muse agent synced over 187,000 rows of his Mac's Messages database.Aten said he never gave the agent permission to access those messages and confirmed that his Mac's "Full Disk Access" was disabled.Meta countered by arguing that bypassing Apple's security mechanisms is difficult and that Muse requires multistep user consent before proceeding with such agent activity.

But the red flag here is when Aten explicitly asked Muse how it knew about his private conversations: the personal agent appeared to hallucinate.It fabricated a story about reading them from incoming notifications, not knowing its full security architecture.Regardless of the cause of the incident — whether it was a macOS bug or user error — the outcome is unacceptable.

You shouldn't trust a black-box agent with access to a large amount of your private data, especially when it can't reliably explain what data it accessed or how it obtained it.Related 5 Gemini Spark prompts that save me hours every week Stop wasting time on digital chores—these five Gemini Spark prompts put my inbox, streaming picks, and weekly schedule on autopilot Posts By  Vishwamoorthy Ramakrishnan Muse gave a stranger a reviewer's home address without asking What happens when an assistant lowballs your listing and sends a buyer to your door When a chatbot like ChatGPT or Gemini hallucinates, the consequences are usually limited to the information it gives.But when an autonomous personal agent does the same, the mistake can instantly create a real-world safety risk by even sending a stranger to your doorstep.

Consumer tech reviewer Matt Robb discovered this after granting Muse permission to manage his Facebook Marketplace listings.By selecting Always allow on an automated reply prompt, he let the agent handle conversations on his behalf.Without notifying Robb, Muse negotiated a lowball offer for his keyboard, sent his home address to a prospective buyer, and finalized the meetup.

When the buyer arrived at Robb's place, Muse texted, even though Robb wasn't at the apartment.The agent then fabricated an excuse when the buyer asked about his availability.Later, when Robb discovered what had happened, he immediately told Muse to stop sending his personal address to buyers.

But the agent ignored the instruction and sent the address to five more test accounts.Muse hoards 31 data categories to feed its models Ranks top on the data collection index Agents require broader system permissions and visibility than isolated chatbots to handle complex workflows, but Meta Muse sets a new benchmark for data collection.According to an audit by VPN firm Surfshark analyzing App Store privacy disclosures, Muse collects or attempts to collect 31 of 35 recognized data types, including contact info, precise location, and search history.

That puts Meta's AI products (Meta AI and Muse) right at the top of the index, collecting nearly twice the number of data types (33) compared to regular chatbot apps like ChatGPT (17).Additionally, Meta has enabled model training by default on all your Muse interactions.You never know what aspect of your daily workflow data could be used for future model training, which is alarming.

Related Your Android phone is checking location 500+ times daily—here's how to stop it I dug into Android's Permission History and found apps pinging my GPS 500+ times a day.Here is how I reclaimed two hours of battery life.Posts 15 By  Vishwamoorthy Ramakrishnan Convenience is never worth trading away your privacy While the idea of offloading the cognitive load of searching for products, adding them to your cart, or booking a reservation with a personal AI agent sounds fun, it comes with trade-offs — especially when the agent comes from a data-driven company like Meta, whose sole purpose is to collect as much data as possible.

So it's always best to use these tools cautiously and understand what data and permissions you're giving them.

Read More
Related Posts