I went looking for the exploit.
The claim circulating is blunt: Muse, Meta’s new personal AI assistant, carries a serious 0-day. That’s a strong accusation about a product that just shipped. So I did the thing reviewers are supposed to do before amplifying a scare, which is ask what’s actually on the record. And what’s on the record is thinner than the headline suggests. The verifiable material covers Muse’s launch and its feature set. It says the assistant has been tested with safety protections and hardened against vulnerabilities through a bug-bounty program. There’s no published advisory, no proof-of-concept, no affected-version list, no disclosure timeline.
So I’m not going to pretend I’ve seen one. If a reviewer can’t point to the bug, the reviewer doesn’t have the bug.
What Muse actually is
Strip away the noise and the product is interesting on its own terms. Muse is Meta’s push into personal AI agents, part of what the company is calling the Muse Spark family. It’s reachable through the web, through mobile apps, and through WhatsApp, with integration into Meta’s AI glasses coming. Mark Zuckerberg has framed supercharged digital assistants as the next big leap for AI models, and he’s used that framing to justify Meta’s heavy spending on data centers and infrastructure.
The feature everyone fixated on is phone calling. Muse can place calls on your behalf. Reuters reported on September 22 that Meta has been testing a “human concierge” for the assistant, meaning human contractors quietly handle some of the calls placed through the digital agent. Not all of them. Some.
The real exposure isn’t a CVE
Here’s where I’ll give the 0-day crowd partial credit, because their instinct is pointed at something true even if their evidence isn’t.
The word in the topic line that matters is “privileged.” An assistant that lives inside WhatsApp, runs on your phone, sits on your face via glasses, and dials phone numbers for you is not a chatbot you poke at in a browser tab. It’s an agent with reach. The attack surface of a system like that isn’t one memory bug in one binary. It’s the whole chain of permissions you hand over so the thing can be useful.
And then there’s the concierge. A human contractor quietly completing calls that a user believes an AI is handling is not a software vulnerability. It’s a trust and disclosure question, and in some ways it’s harder to patch than code. Consider what it implies:
- A person, not a model, may be on a call initiated on your behalf.
- Whatever context the agent needs to make that call useful is context a human may see.
- The party on the other end of the line has no obvious way to know which is which.
- “Quietly” is doing a lot of work in that sentence.
None of that requires an exploit. It’s the designed behavior. If you’re worried about a privileged assistant leaking things it shouldn’t, the documented human-in-the-loop is a more concrete concern than an undocumented bug.
Timing nobody at Meta chose on purpose
TechCrunch made the observation I keep coming back to. Meta announced its biggest consumer AI bet to date less than two weeks after agreeing to an $18 billion multistate settlement in a lawsuit over social media’s consumer harms. That sequencing shapes how every safety claim about Muse gets received, fairly or not. A bug-bounty program is a reasonable thing to have. It is also the kind of thing a company mentions when it anticipates being asked whether it has earned the benefit of the doubt.
That’s the actual difficulty for Muse, and a bounty program doesn’t solve it. The assistant needs permission to be useful, and the company asking for permission is the one that just wrote a settlement check over consumer harm.
My read
Treat the 0-day story as unproven until somebody publishes. If a real disclosure lands with technical detail attached, that changes the picture and I’ll say so. Rumors about security bugs in brand-new, heavily covered products are cheap, and they crowd out the harder conversation.
The harder conversation is this. Muse is an agent with phone access, multi-platform reach, a wearable roadmap, and a human fallback layer that users may not notice. Each of those is a deliberate product decision, each one expands what the assistant can touch, and each one is more consequential than a hypothetical patch note.
If you’re evaluating Muse right now, ask what it can reach and who else can see it. That’s the question worth pressing on. The exploit may or may not exist. The permissions definitely do.
🕒 Published: