Security Flaw in Meta’s Muse AI Assistant Raises Concerns Over User Data
Meta is strengthening security warnings within its Muse AI assistant after a security flaw was discovered that could potentially have exposed sensitive user information.
The vulnerability was reported by an external security researcher through Meta’s bug bounty program. According to an internal incident report reviewed by The Information, the flaw could have allowed an attacker to gain access to a user’s dedicated virtual environment in the cloud, which may contain personal data such as emails and stored files.
Meta initially classified the vulnerability as “SEV-2,” the third-highest severity level on its five-level security scale. The classification is generally used for incidents considered to have a significant potential impact.
The discovery comes shortly after Meta launched Muse, a personal AI agent designed to perform tasks on behalf of users, including shopping, travel bookings, sending emails and making payments.
Muse has gained traction since its launch, reaching the top of the free-app rankings in the United States and Canada on Apple and Google’s app stores. Market research firm Sensor Tower estimated that the application recorded around 2.8 million downloads during its first two weeks.
The incident highlights the security challenges associated with AI agents that are granted access to sensitive user accounts and services. As these systems become capable of carrying out tasks independently, protecting cloud environments and personal data remains a key security concern.
