Meta strengthens Muse warning after bug bounty flaw, Reuters reports
Reuters, citing The Information, says a researcher found a flaw that could have exposed a Muse user's dedicated virtual machine, and that Meta is making a safety warning clearer.

Meta is adding a clearer safety warning inside Muse, its personal AI agent, after an outside researcher reported a vulnerability through Meta's bug bounty programme, Reuters reported on Friday 25 September 2026, citing The Information.
What was reported
Reuters, citing The Information, reported that:
- The flaw "could have allowed an attacker to access a user's dedicated virtual machine — an individualized cloud-based account containing data including emails and files", according to an internal Meta incident report reviewed by The Information.
- It was reported "by an outside researcher through Meta's bug bounty program" and had not previously been disclosed.
- It was initially classified as a "SEV-2", which Reuters described as Meta's "third-highest severity level on a five-point scale, typically used for incidents with significant impact".
Reuters said: "Meta did not immediately respond to a Reuters request for comment."
A separate write-up by Stocktwits, also citing The Information, added two details that are not in the Reuters report:
- It said a Meta spokesperson confirmed the flaw "was initially miscategorized and subsequently downgraded to 'SEV-3'".
- It said that to exploit the flaw "an attacker would need to trick a user into asking Muse to summarize or process a link to a compromised webpage", and the user "would then have to manually select 'allow' on a system prompt containing a security notice". Stocktwits said Meta is increasing the visibility of these alerts in response.
Stocktwits described SEV-2 as Meta's "second-highest" rating, which differs from Reuters' "third-highest". We have not been able to read The Information's own report, which is paywalled, so we cannot say which is correct. Neither the Reuters report nor the Stocktwits piece says whether the underlying flaw has been fixed (Stocktwits does say Meta has deployed a fix for a separate Mac-app flaw), and we have not found a public write-up by the researcher, who has not been named.
What Muse is
Meta introduced Muse on 8 September as "a secure, private personal AI agent that proactively helps with people's goals and suggests ideas". Reuters described it as an agent "designed to carry out tasks such as shopping, travel booking, emailing and payments on behalf of users", and said Sensor Tower estimated about 2.8 million downloads in its first two weeks.
The "dedicated virtual machine" in the reports is central to Meta's design. In Meta's words:
- Muse runs on "Muse Secure VM, a dedicated, virtual machine (VM) that houses both the agent and a person's data".
- "Muse runs on its own dedicated computer in the cloud, contained so no one else's agent can reach it. That is where Muse lives and where the data and credentials for any service a person connects are securely stored."
- "A separate Sentinel agent runs on that same machine, kept apart from Muse at the system level. Nothing Muse does reaches the internet unless the Sentinel approves it, and it asks the person for permission when needed."
Meta's safety write-up, published the same day, says the system was designed "to assume the agent may be under attack and limit the potential damage". It says that when approval is needed, "A dialog is presented to the user directly within the client UI", and that "The point is not to ask the user about everything." On our reading of Stocktwits' account, it appears to be that kind of user approval that stood between the attacker and the data in the reported attack.
The same post opened the Muse bug bounty to everyone at launch. Meta said the programme "awards up to $300,000 for valid reports, including up to $130,000 for successful prompt injection attempts that affect one user". Reuters' report does not say what the researcher was paid.
How this relates to Muse Glimmer
We previously covered Meta's Muse Glimmer, a 30B open-weights model made for local agents. Glimmer is a model, not the Muse agent. Meta says the Muse agent is "powered by Muse Spark", and that it trained Glimmer "on Muse Spark's outputs using logit distillation" — so the two share a model family, but nothing in the reports concerns Glimmer.
Why it matters
On our reading, this is the bug bounty route working as intended: a flaw reported privately to Meta first, rather than found in the wild. The open questions are the ones the reporting leaves unresolved — the exact severity rating, whether the underlying flaw has been fixed as well as the warning strengthened, and how much protection rests on a user reading a prompt before clicking "allow". Meta's own safety post says it expects to tune the balance of user approvals "over time as we have more experience with real users".
- Meta bolsters Muse safety warning after security vulnerability found, The Information reports (Reuters, via WHBL)
- Exclusive: Meta Bolsters Muse Safety Warning After Security Vulnerability Found (The Information, paywalled)
- META Stock Drops 3.4%: Meta Reportedly Moves To Strengthen Safety Alerts After Muse Security Issue Discovery (Stocktwits, via Yahoo)
- Introducing Muse (Meta Newsroom)
- How We Built Safety Into Muse (Meta AI Research)
- Introducing Muse Glimmer (Meta AI Research)
Ask Relay — he reads every question himself and replies personally by email.
