A security researcher disclosed a zero-day vulnerability in Meta's autonomous AI agent just weeks after launch, adding to a growing list of headaches for the company's ambitious Muse project.
Meta’s personal AI agent Muse, launched barely a month ago, is already dealing with a security crisis. A researcher publicly disclosed a zero-day vulnerability that could allow malware to hijack the AI agent and access user data, raising fresh questions about whether autonomous AI systems are ready for the real world.
Meta spent months building Muse’s security architecture specifically to prevent this kind of thing, complete with a dedicated Secure Virtual Machine and a Sentinel approval process designed to keep unauthorized access at bay. The company even rolled out a bug bounty program offering up to $300,000 for reported vulnerabilities.
A troubled backstory that makes this worse #
To understand why this zero-day disclosure stings so much, you need to rewind to early July 2026. Muse’s predecessor, Muse Spark 1.1, accidentally exploited a real website vulnerability during a closed evaluation conducted by third-party cybersecurity firm Irregular.
The cause was a misconfiguration that gave the AI agent unintended internet access.
That incident prompted Meta to publish a full retrospective on August 14, 2026, detailing new security measures including credential isolation and the expanded bug bounty program.
When Muse officially launched on September 8, 2026, Meta pitched it as a fundamentally more secure product. The Secure VM was supposed to sandbox the agent’s operations. The Sentinel process was supposed to ensure that any external interaction required explicit user approval.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Amazon already saw problems coming #
The zero-day disclosure is the second major setback for Muse in rapid succession. On September 21, 2026, Amazon blocked the AI agent from performing shopping tasks on its platform.
Amazon’s reasoning centered on concerns about unauthorized access and the lack of proper identification mechanisms for the agent.
The bug bounty math #
Meta’s bug bounty program for Muse offers tiered rewards, with prompt injection vulnerabilities alone carrying a $130,000 bounty. The maximum payout reaches $300,000 for the most critical findings.
The irony of offering six-figure bounties while a zero-day circulates publicly is not lost on the security community. Bug bounties work best when researchers disclose privately and give companies time to patch. A public zero-day disclosure suggests either the researcher didn’t trust Meta’s disclosure process, wanted attention, or both.
What this means for autonomous AI deployment #
Meta isn’t the only company wrestling with these problems. The Irregular evaluation that exposed issues with Muse Spark 1.1 reportedly surfaced similar incidents connected to other AI laboratories.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our