Vulnerability Found in Meta Platforms' AI Agent 'Muse' ... "Warnings to Be Strengthened"
- Input
- 2026-09-27 14:16:56
- Updated
- 2026-09-27 14:16:56

According to The Information, a U.S. IT news outlet, on the 26th local time, the vulnerability could have allowed hackers and other attackers to access a dedicated cloud virtual machine (VM) storing users' personal data. The hacking attack could occur when a user provided Muse with a link to a malware-infected website and asked it to summarize or organize the content. The vulnerability was identified through Meta Platforms' bug bounty program.
In response, Meta Platforms decided to display a prominent warning message whenever a website is suspected of being infected with malware, making it easier for users to recognize the risk. Meta Platforms initially classified the vulnerability as SEV-2, the second-highest of five severity levels, but later downgraded it by one level to SEV-3.
Regarding Muse's security, Meta Platforms previously explained, "Muse is not completely immune to attacks. Muse sometimes makes mistakes," adding, "It was designed to minimize the impact when problems occur and allow users to remain in control of the situation."
Billed by Meta Platforms as the "world's first personal agent," Muse is an AI assistant that can write emails, make travel reservations and complete purchases on behalf of users. Within two weeks of its launch, Muse ranked first among free apps on the app stores in the United States and Canada. Market research firm Sensor Tower estimated that the Muse app had been downloaded approximately 2.8 million times.
[email protected] Hong Chae-wan Reporter