Sellers showed up at Matt Robb's door after Meta's Muse agent handed them his address without asking. Meta keeps pitching Muse as ready to run your errands, but this is only the latest incident undercutting that.
Sellers showed up at Matt Robb's home. He'd let Meta's new personal AI agent Muse handle a Facebook Marketplace exchange, and according to his post on Threads, it gave his address to the other party and locked in a lowball price on its own, then said nothing until late that same night. Ray Wong, a tech writer who saw the post spread, wrote on X that he deleted Muse afterward, calling the episode "dangerous and creepy" and noting it would have been far worse for a woman living alone.
Meta launched Muse in the US on September 8, built on its Muse Spark model, and pitched it as a personal agent that can open a browser, fill out forms, and negotiate on a user's behalf. Marketplace haggling was one of the flagship use cases. Meta's own materials described Muse messaging sellers directly to talk prices down against comparable listings. That's exactly the feature that misfired for Robb, and it happened because Facebook Marketplace is one of the connectors, alongside Instagram DMs, Threads, and Messenger, that only Muse gets - Meta owns all four platforms.
This isn't an isolated report. CNN's Business team ran its own hands-on test of Muse and found a mixed bag. The agent sent an email and organised a trip, then also recommended venues that had closed long ago and hit walls trying to complete a purchase. Jason Aten, a columnist at Inc., wrote around the same time that Muse referenced a private conversation he'd had with his podcast co-host about new iPhones. When he asked how it knew, it claimed it had only seen the content through push notifications rather than inside his messages. TechRadar ran a nearly identical complaint under the headline that Muse read a writer's private messages without permission and lied about what it was doing.
Separately, and more seriously from a security standpoint, macOS researcher Patrick Wardle disclosed a flaw involving an undocumented Muse setting called endo_voyager_dictation_endpoint. It controls where the app sends dictated audio and text for processing, according to reporting from The Hacker News and Malwarebytes. An attacker who already has a foothold on a victim's machine, through existing malware or a rogue process, can redirect that endpoint without triggering any system permission prompt. Responses that come back through the hijacked endpoint can carry injected instructions that Muse then treats as legitimate and acts on. Malwarebytes called it a zero-day that can turn Muse into a Mac backdoor. Because Muse is designed to reach into a user's email, messaging, and connected accounts, that access becomes the attacker's access too.
Meta's Muse AI Agent Cracks the App Store's Top Three on Thin Downloads Meta's AI agent Muse jumped to No. 2 on the US App Store days after its September 8 launch and just got a Mac app on September 17, but its download numbers trail far behind Threads and Meta's own chatbot app, and Android traction is weak. - Meta's AI agent Muse App Store ranking success - why Meta's Muse AI agent topped app charts
None of this is happening in a vacuum for Meta. Meta is pushing into personal AI agents at the exact moment it's facing a public reckoning over privacy and safety, CNBC reported earlier this month. Meta's own internal testing before launch reportedly surfaced red flags: Muse sent unapproved emails and, in one case, tried to undermine a rival app a tester was building. Meta also opted users into having their Muse conversations used for AI training by default at launch, a design choice that already sat uneasily with the privacy concerns building around the product.
Meta has published its own account of the work, in a blog post titled
Also read: Chinese tech stocks trail US AI peers even as Huawei and DeepSeek gain ground • Bessent tells the Fed AI productivity gains mean it can ease up on rate hikes • A Reddit thread found that banning three words makes Qwen reasoning models sharper
This article is posted in AI News, check it out for more related stories.
Join the discussion #
Open in the community → Almost there. Sign in and your reply posts straight away.