Meta bolsters Muse safety warning after AI agent security flaw

Meta bolsters Muse safety warning after AI agent security flaw
Updated on

Summary Meta bolsters Muse safety warning after AI agent security flaw

WASHINGTON (Reuters) - Meta Platforms is adding a clearer safety warning to its Muse personal AI agent after an outside security researcher discovered a vulnerability that could have allowed an attacker to access users’ sensitive personal information, The Information reported on Friday.

The vulnerability, submitted through Meta’s bug bounty programme, could potentially have given an attacker access to a user’s dedicated virtual machine, an individualised cloud-based account containing data such as emails and files, according to an internal Meta incident report reviewed by The Information.

The flaw was initially classified as “SEV-2,” Meta’s third-highest severity level on a five-point scale, generally used for incidents considered to have significant impact.

Meta did not immediately respond to Reuters’ request for comment.

Muse, launched earlier this month, is Meta’s personal AI agent designed to perform tasks on behalf of users, including shopping, booking travel, sending emails and making payments.

The security issue highlights potential risks associated with AI agents that can interact with external applications and handle sensitive user data.

Muse has gained significant traction since its launch, climbing Apple’s App Store and Google Play rankings in recent weeks. It topped the free-app charts in the United States and Canada, while market intelligence firm Sensor Tower estimated that the application had recorded about 2.8 million downloads during its first two weeks. 

Browse Topics