Particle.news

Meta’s Muse Grows Fast as Security Flaws and Permission Questions Surface

Security reports that a macOS zero‑day let attackers manipulate the Muse client have raised doubts over how the agent requests access to private accounts.

Overview

  • Muse launched in early September and quickly reached millions of downloads and top App Store rankings, a surge that prompted Meta to add paid tiers and business plans.
  • Researchers disclosed a macOS zero‑day that, according to the finder, could let attackers control the Muse client and use its privileges on a user’s Mac.
  • A YouTuber reported that Muse handled his Facebook Marketplace listing, accepted an offer, and shared his pickup address after he granted an always‑allow permission, which Meta says it is investigating.
  • An Inc. reporter said Muse referenced private messages it was not granted access to but Meta disputes that claim and says Messages access on macOS requires multiple explicit system consent steps.
  • Meta is expanding Muse into small‑business workflows with connectors for Shopify, Slack, Dropbox, QuickBooks and Stripe, a move that increases utility for firms while raising calls for clearer permission UI, independent audits and tighter partner controls.