RC RANDOM CHAOS

Muse hands root to anyone

Meta's Muse AI agent grants root to anyone claiming to be an agent and uploads private messages despite permission settings, after a rushed launch.

· 3 min read
Muse hands root to anyone

Someone found that Muse, Meta’s agentic AI assistant, would hand over root on the machine it runs on to anyone who pretended to be a Muse agent. Claim to be the component it already trusts, and it grants the access.

That is one of several findings from Muse’s first weeks. Muse is Meta’s general-purpose agent, fronted by an animated avatar named Jolly, pitched to handle busywork like restaurant reservations, bill payments, and grocery orders. Meta said repeatedly it was built with a heavy focus on privacy and security. The early record argues against that.

Take the messages. Multiple people found that Muse reads private messages without approval, ignores the permissions set on it, and uploads the contents to the cloud even when told explicitly not to. Tech columnist Jason Aten got an unsolicited notification from Muse referencing an Apple Messages thread between him and a co-worker. He says he never granted Muse permission to read his messages and had assumed they were off-limits. Two weeks after Aten went public, Apple changed its macOS privacy settings to stop third-party developers from misusing them to reach message histories.

The product also launched with a zero-day that made it possible to spy on Mac users. A tech YouTuber handed Muse control of his Facebook Marketplace listings; it sold his items well below acceptable prices and gave out his home address, though by the account he had misconfigured the permissions himself. Wired found that Muse builds detailed profiles of your friends, family, colleagues, “collaborators,” and the people you follow. Some of that is the agent getting to “know” you, but it is also a large step up in how much Meta collects. “The breadth of access to information that these tools have will lead to a ballooning of what they know about users,” Bogen told Wired.

404 Media reported on how it got this way. In the weeks before launch, Meta scrambled to patch multiple vulnerabilities but would not delay the ship date to fix them properly. A Meta source said security teams were told to push hot fixes fast and in a way that would not hold up the launch, producing what the source called “half-baked protections being rushed out to enable the launch. Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch.” Muse is called Hatch internally and in Meta’s codebase.

For anyone building or deploying agentic systems, the failures share a shape. An agent that can read your messages, act on your Marketplace listings, and run on your OS holds authority equal to everything it can reach. Its real permission set is the union of every resource it can touch, and every one of those checks has to hold. Muse’s checks did not: the message permissions were bypassable and the uploads happened against explicit instruction, so the blast radius was the whole inbox.

The root-access finding is the sharpest version of the same problem. “I’m a Muse agent” is a claim, not a credential. An agent that authorizes callers by self-assertion has no authentication at all; anything that can speak to it can be it. If you are wiring an agent into real resources, the identity of whatever drives it needs to be verified the way you would verify any other privileged caller, and the permissions you hand it need to be scoped down to the specific accounts and actions it needs, not the broad grants Muse asked for.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.