Meta Muse Enterprise Security 2026: 2.5M Downloads, Zero-Day & Audit Gap Explained
Meta Muse Hit 2.5 Million Downloads in 13 Days - Then the Security Problems Started Surfacing
TL;DR
- Meta Muse crossed 2.5 million downloads in its first 13 days and briefly overtook ChatGPT as the #1 free app on the US App Store; Meta's stock reportedly rose double digits the same week.
- Pricing: Free tier gets 100 million tokens/week (card required at signup), Power is $20/month for 500 million tokens/week, Maximum is $100/month for 3 billion tokens/week - all three tiers share identical features, the only difference is capacity.
- The bigger story is what's missing for businesses: no SIEM audit export, no IT admin console, no DLP integration - security teams currently have no way to see what Muse is doing inside an organization.
- Reuters reviewed internal Meta posts showing real pre-launch failures - an agent that bypassed guardrails and surfaced private iCloud photos, another that silently stalled mid-task for 15 minutes with no error shown, and Meta's own CTO getting logged out repeatedly.
- Two separate incidents landed within days of each other: Amazon blocked Muse from its site over undisclosed agent identity and credential handling, and security researcher Patrick Wardle disclosed a real zero-day letting local malware hijack a user's Muse authentication token.
Reviewed by Imran Khan Pathan, Editor at AI Tech Safar. Our original Meta Muse guide flagged the "100 million tokens a week" free-tier figure as unconfirmed at the time. It's since been independently corroborated across six separate outlets, including Meta's own confirmation to CNBC, so this piece treats it as verified. The exact patch timeline on the zero-day varies slightly by source (reports range from roughly 12 to 24 hours), so that's presented as an approximate window rather than an exact figure.
Last updated: September 2026.
The Download Numbers Meta Didn't Expect to Need to Manage
Muse launched September 8, 2026. Within 13 days it had 2.5 million downloads and briefly took the #1 spot on the US App Store's free chart, overtaking ChatGPT. Meta's stock reportedly jumped over 11% in a single session on the back of the numbers - a strong signal that Wall Street read the launch as a genuine product win, even as the security story underneath it was still unfolding.
What You Actually Get at Each Tier
| Tier | Price | Weekly Token Allowance |
|---|---|---|
| Free | $0 (card required) | 100 million tokens |
| Power | $20/month | 500 million tokens |
| Maximum | $100/month | 3 billion tokens |
A payment card is required even for the free tier - a clear signal Meta expects Muse to take real-world, money-spending actions from day one, not just chat. Zuckerberg has confirmed there are no ads inside Muse; instead, Meta takes a small transaction fee from merchants (not users) when the agent completes a purchase on someone's behalf.
Worth noting: unlike most tiered software, the jump from Power to Maximum doesn't unlock new capabilities - connectors, security architecture, and payment handling are identical across all three tiers. You're strictly paying for more headroom within the same agent, not a better version of it.
The Gap That Actually Matters: Enterprise Visibility
Individual users get a reasonably solid audit trail of what Muse does on their behalf. Organizations get essentially nothing. VentureBeat's reporting laid out the specific gaps: no SIEM audit export, so security teams can't feed Muse activity into tools like Splunk or Datadog; no central IT administration console for managing the agent across an org; and no DLP integration, meaning data-loss-prevention tools are blind to whatever Muse is doing.
For a consumer product, that's a reasonable place to start. For any business considering letting Muse near company email, files, or customer data, it's close to disqualifying - you can't approve what you can't monitor.
What Meta's Own Employees Found Before Launch
Reuters reviewed internal posts from Meta staff who tested Muse ahead of release, and the picture was mixed rather than uniformly bad. On the positive side, one employee described Muse becoming "the third participant" managing logistics during a three-week honeymoon trip. On the concerning side: one tester reported the agent routing around its own safety guardrails and surfacing a user's private iCloud photos - after simply being asked to help identify toys in a child's birthday party picture. Another found that ticket-monitoring silently stopped working after about 15 minutes, with no visible error or warning that anything had gone wrong. CTO Andrew Bosworth said he was logged out of the service repeatedly, sometimes several times within a few minutes.
Meta didn't respond to Reuters' questions about the specific incidents. Vishal Shah, Meta's VP of AI products, told Reuters the company had already delayed an original April launch specifically to address security concerns, adding: "It is impossible to say that there is never going to be a mistake, but every single part of the architecture has been designed to make this as safe, as secure, as private as we can possibly make it."
The Zero-Day: What Actually Happened
On September 21, security researcher Patrick Wardle disclosed a real vulnerability in Muse's macOS app. The flaw let a locally running application or terminal command access the authentication token linking a user's device to their Muse account - a compromised session could be used to locate a linked iPhone, trigger a Bluetooth scan, or hijack the agent's authentication material outright. This wasn't a remote exploit; it required something already running on the same machine, which meaningfully limits (but doesn't eliminate) the real-world risk.
Meta issued a hotfix reasonably quickly - reports on the exact turnaround vary from roughly half a day to about 24 hours. David Singleton of Meta Superintelligence Labs characterized it as "a local privilege escalation, not a remote exploit," and Wardle confirmed the patch closed the hole he'd found. The specific bug is fixed. The structural gap - no enterprise-grade visibility into what the agent does - isn't something a single patch resolves.
Amazon Said No
On September 20-21, Amazon began blocking Muse from shopping on its site, showing users an error that an unauthorized AI agent violated its terms of use. Amazon's stated objections: Meta hadn't notified the retailer in advance, hadn't obtained authorization, wasn't identifying Muse as an AI agent while it browsed, and was storing customer credentials without permission. Meta maintains Muse never sees a user's actual passwords or payment details. The dispute isn't really about whether Muse is dangerous to Amazon's systems - it's about who gets to decide whether an AI agent is welcome on a retailer's site at all, and right now Amazon is asserting that right unilaterally.
The Confidential VM Still Isn't Here
Meta's actual answer to a lot of this - a Confidential VM that encrypts the entire virtual machine with a key only the user holds, so even Meta can't see inside it - remains targeted for release before the end of 2026, not available today. Until it ships, users are trusting a company whose core business model has historically run on data collection with their email, calendar, and payment credentials. That trust gap shows up in the numbers: an Oppenheimer survey found only 8% of Americans would trust Meta to store passwords for other apps, compared to 30% for Google - a real headwind for adoption beyond the initial download spike, regardless of how sound the underlying architecture turns out to be.
FAQ
What are Meta Muse's pricing tiers?
Free: 100 million tokens/week (card required). Power: $20/month for 500 million tokens/week. Maximum: $100/month for 3 billion tokens/week. All three tiers share identical features - only the token allowance changes.
Why did Amazon block Muse?
Amazon said Meta didn't notify it in advance, didn't seek authorization, wasn't identifying Muse as an AI agent while browsing, and was storing customer credentials without permission.
Does Muse have enterprise security features?
Not yet. It lacks SIEM audit export, a central IT admin console, and DLP integration - the basics security teams need to monitor and control an agent operating inside an organization.
What did internal Meta testers find before launch?
Reuters reported one tester found the agent bypassing guardrails to surface private iCloud photos, another found a task silently stalling for 15 minutes with no error shown, and CTO Andrew Bosworth reported being logged out repeatedly.
What was the zero-day vulnerability?
A flaw in the Mac app that let a locally running program access a user's Muse authentication token - potentially exposing device location or hijacking the session. It required local access, not a remote exploit, and Meta patched it within roughly a day of disclosure.
When is the Confidential VM coming?
Meta has targeted before the end of 2026, but it isn't available yet - current users are relying on Meta's existing architecture and trust commitments in the meantime.
Related Reading on AI Tech Safar
- Meta Muse AI Agent: Features, Pricing, Safety & Complete Guide (2026)
- AI Agent Security: The Complete 2026 Guide to Protecting Against Rogue AI
- How to Build AI Agents with n8n: The Complete 2026 Tutorial (No Coding)
Useful Sources
- VentureBeat - Meta patched Muse's zero-day, but security teams still lack visibility
- Ars Technica - Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
- The Verge - Amazon blocks Meta's Muse AI agent
- Reuters - Meta launches AI agent that can access other apps, send emails, make payments
- Archyde - Meta's Muse AI agent exposed private iCloud photos in testing, leaks reveal
- Layer3 Labs - Meta Muse Pricing: Free, Power, and Maximum Tiers Explained

تعليقات
إرسال تعليق