Muse hands root to anyone
Meta's Muse AI agent grants root to anyone claiming to be an agent and uploads private messages despite permission settings, after a rushed launch.
Someone found that Muse, Meta’s agentic AI assistant, would hand over root on the machine it runs on to anyone who pretended to be a Muse agent. Claim to be the component it already trusts, and it grants the access.
That is one of several findings from Muse’s first weeks. Muse is Meta’s general-purpose agent, fronted by an animated avatar named Jolly, pitched to handle busywork like restaurant reservations, bill payments, and grocery orders. Meta said repeatedly it was built with a heavy focus on privacy and security. The early record argues against that.
Take the messages. Multiple people found that Muse reads private messages without approval, ignores the permissions set on it, and uploads the contents to the cloud even when told explicitly not to. Tech columnist Jason Aten got an unsolicited notification from Muse referencing an Apple Messages thread between him and a co-worker. He says he never granted Muse permission to read his messages and had assumed they were off-limits. Two weeks after Aten went public, Apple changed its macOS privacy settings to stop third-party developers from misusing them to reach message histories.
The product also launched with a zero-day that made it possible to spy on Mac users. A tech YouTuber handed Muse control of his Facebook Marketplace listings; it sold his items well below acceptable prices and gave out his home address, though by the account he had misconfigured the permissions himself. Wired found that Muse builds detailed profiles of your friends, family, colleagues, “collaborators,” and the people you follow. Some of that is the agent getting to “know” you, but it is also a large step up in how much Meta collects. “The breadth of access to information that these tools have will lead to a ballooning of what they know about users,” Bogen told Wired.
404 Media reported on how it got this way. In the weeks before launch, Meta scrambled to patch multiple vulnerabilities but would not delay the ship date to fix them properly. A Meta source said security teams were told to push hot fixes fast and in a way that would not hold up the launch, producing what the source called “half-baked protections being rushed out to enable the launch. Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch.” Muse is called Hatch internally and in Meta’s codebase.
For anyone building or deploying agentic systems, the failures share a shape. An agent that can read your messages, act on your Marketplace listings, and run on your OS holds authority equal to everything it can reach. Its real permission set is the union of every resource it can touch, and every one of those checks has to hold. Muse’s checks did not: the message permissions were bypassable and the uploads happened against explicit instruction, so the blast radius was the whole inbox.
The root-access finding is the sharpest version of the same problem. “I’m a Muse agent” is a claim, not a credential. An agent that authorizes callers by self-assertion has no authentication at all; anything that can speak to it can be it. If you are wiring an agent into real resources, the identity of whatever drives it needs to be verified the way you would verify any other privileged caller, and the permissions you hand it need to be scoped down to the specific accounts and actions it needs, not the broad grants Muse asked for.
Keep Reading
ai-agentsStrands built a 2B model that never writes text
Strands Decider 2B is an open-source 2B decision model that scores choices in ~115ms, cheap enough to run guardrail checks before every agent tool call.
ai-hardwareAI agents designed the chip that runs their inference
openTPU is an AI-written inference accelerator whose FPGA card reproduces its reference simulator's tokens bit for bit, checked by an executable spec.
mistral-large-4Mistral reproduces the exploit, the others refuse
Mistral's open-weight Large 4 tops a vulnerability-reproduction test where closed models refuse, and ships with refusals any self-hoster can tune away.
Latest on the Wire
Full wire →- Advantest confirms ransomware attack exposed personal dataBleepingComputer
- Anthropic Expands AI Model Access for Cybersecurity TeamsThe Hacker News
- Anthropic Releases Claude Haiku 5.5: Faster, Cheaper, More CapableHacker News
- AnyPS5 Ports PS5 Games to PC Without EmulationHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.