Meta’s Muse AI agent raced past ChatGPT in downloads, then a zero-day security flaw emerged

Muse drew more than 2.5 million downloads in under two weeks and can handle entire tasks for users, but the sweeping permissions that make it useful also became its weak point after a researcher disclosed a flaw that could expose account access

Meta has scored an early success in the artificial intelligence race, with its new AI agent Muse climbing to the top of download charts less than two weeks after launch and, in initial figures, even outpacing ChatGPT, Claude and Grok.
Muse launched on September 8 and recorded about 730,000 installations in its first five days. By Monday, that figure had climbed above 2.5 million. Preliminary data from market intelligence firm Sensor Tower showed that during its first 12 days, Muse recorded about 1.8 million iPhone downloads in the United States and Canada, compared with about 1.3 million for ChatGPT over the same period.
Muse, סוכן ה-AI החדש של מטא
Muse, סוכן ה-AI החדש של מטא
Muse
(Photo: Screenshot)
Actual usage figures have also been strong. Muse reached about 359,000 daily active iPhone users in the United States and Canada.
And that does not include people who use the service without downloading the app at all. Meta also makes Muse available through WhatsApp, meaning its total user base may be significantly larger.
Meta’s existing ecosystem has likely contributed to that rapid adoption. More than 95% of Muse users also use Facebook, while about 63% use Instagram.
In other words, unlike AI companies that must build an audience largely from scratch, Meta already has billions of potential users inside its apps.

Then the problems began

The more significant story behind Muse, however, is not simply its download numbers, but what Meta is trying to make the system do.
Unlike chatbots such as ChatGPT, where users ask a question and receive an answer, Meta defines Muse as an “autonomous personal agent,” a system designed to receive a goal, determine the steps required to complete it and then carry out those steps itself.
Instead of asking an AI to find a hotel and then visiting a website to book it yourself, the idea is for Muse to handle the entire process.
It can browse the web, connect to services used by the user and perform tasks including sending emails, booking flights and hotels, managing calendars, reserving restaurant tables, sorting email, dealing with customer service requests, comparing prices and even negotiating online purchases.
Muse is based on Meta’s Muse Spark 1.3 foundation model and can connect to email accounts, calendars and payment services, among other platforms.
The idea is that the agent will not simply answer a request, but continue working even after the user has closed the app.
To make that possible, Meta says each user is effectively assigned a separate virtual computer in the cloud that runs continuously and is dedicated exclusively to that user. The agent can carry out tasks on that machine while keeping different users’ activity separated.
מנכ"ל מטא, מארק צוקרברג
מנכ"ל מטא, מארק צוקרברג
Mark Zuckerberg
(Photo: Getty Images)
But that is also where the vision becomes more complicated. Once an AI agent is given access to email, calendars, shopping sites and payment services, a mistake no longer ends with a wrong answer on a screen. It can translate into a real-world action.
Meta itself acknowledges that even a well-trained agent can make mistakes or become a target for attackers.
That concern quickly became tangible. Cybersecurity researcher Patrick Wardle recently disclosed what he described as a zero-day vulnerability in the Mac version of Muse that could allow a local application or command running on the computer to effectively take control of a user’s account.
According to Wardle, the flaw allows an attacker to change the server to which Muse sends transcription data, redirecting it to a server under the attacker’s control and thereby obtaining the token used to access the account.
From there, he said, an attacker could exploit permissions already granted to the agent to perform actions on the user’s behalf, including writing files to the computer and even taking pictures with the camera, in some cases without the user receiving a warning.
The issue is particularly serious because Muse requires broad permissions in order to perform its intended role.
The app can be granted access to email, WhatsApp, calendars and social media accounts, while on a Mac it may also receive permission to access system resources including files, the camera and microphone.

Amazon already said no

Despite the enthusiasm from users, Amazon said it had blocked Muse from accessing its services because of privacy and security concerns.
The e-commerce giant said it had not received advance notice about the integration and argued that persistent, unauthorized access by an AI agent to its services violates its terms of use.
Amazon’s response highlights one of the biggest challenges now facing AI agents. To be genuinely useful, these systems need access to other online services and must be able to act there on a user’s behalf. But those websites and services may not necessarily want autonomous bots browsing their platforms, making purchases or collecting information.
אפליקציית אמזון
אפליקציית אמזון
(Photo: Tada Images / Shutterstock)
For now, Muse is offered on a basic free tier, alongside a $20-a-month subscription and a premium plan costing $100 a month. At least for the time being, Meta has chosen not to include advertising in the service.
That model places the company in direct competition with OpenAI, Anthropic and other AI firms trying to turn paid subscriptions into a major source of revenue.
Investor enthusiasm has also reached Meta’s stock. Meta shares have climbed about 25% during September, putting the stock on course for its strongest month in more than two years. Analysts at Wells Fargo and Citi have raised their price targets amid momentum surrounding Meta’s AI products and Muse’s early adoption.

The battle for AI agents

Muse’s initial success comes just as the AI industry is beginning to shift from familiar chatbots toward autonomous agents.
Instead of waiting for a user to provide instructions at every stage, an AI agent receives a task and breaks it down into steps on its own. It can move between websites, use different tools, make decisions along the way and continue until the task is complete.
That transition is also one reason technology companies are pouring enormous sums into infrastructure capable of running such systems at scale.
Meta expects capital expenditure this year of between $130 billion and $145 billion, much of it directed toward AI infrastructure. At the same time, it is working with chipmaker Arm on processors and specialized chips for its data centers.
The company is also expanding its investments beyond data centers themselves. Meta recently announced Petal, a new undersea cable planned to connect the United States and France that the company describes as the first transoceanic cable with petabit-scale capacity.
Muse also has an interesting connection to OpenClaw, the autonomous-agent project that attracted significant attention across the industry.
The developer behind OpenClaw said Meta had not copied his project, but had instead built its own system inspired by the concept.
A Meta executive also acknowledged that the aim was to create something similar to OpenClaw, but make it safe, secure and simple enough to reach a massive audience.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""