Share this story

FOX NEWS

Last week, Skip Bayless returned to ESPN to reunite

E NEWS

Watch: KATSEYE’s Sophia Laforteza Pulls Out of Group’s European

SPORTS ILLUSTRATED

England enjoyed a first win of the 2026–27 UEFA

Portable Bluetooth Speaker
Outdoor Travel Essentials

Meta’s Muse Is Misbehaving in Mysterious Ways With Your Privacy

Meta debuted its Muse AI assistant this month, so you’ve probably already seen Jolly, its cute Labubu-esque mascot, popping up on Facebook, Instagram or WhatsApp.

In terms of publicity, you could say the cuddly character has been largely successful. But in terms of privacy and security, it’s hard to imagine a more disastrous launch for an AI agent.

Last week, security experts flagged a zero-day vulnerability that the company had to patch quickly. After ZDNET, CNET’s sister site, conducted extensive testing on Muse, an AI expert determined it to be the worst for privacy in comparison with other AI agents from OpenAI, Google and Anthropic.

More from CNET

For starters, Muse requests extensive access to personal data, including passwords, full disk access, email messages, calendar, contacts, Notes and WhatsApp. By default, Meta also appears to use your interactions with Muse to train its AI models, so you have to manually opt out in the settings.

If that wasn’t enough, there’s also a widely publicized case in which Muse mistakenly shared the home address of a Toronto tech reviewer, Matt Robb, with a potential buyer on Facebook Marketplace. Muse invited the stranger to Robb’s home without his explicit consent or knowledge, then later apologized for doing so, as detailed in a Threads post. Robb hadn’t realized that he had inadvertently granted Muse blanket permission to automatically reply to Marketplace inquiries using the details he provided, including his address.

CNET AI Atlas badge; click to see more

AI agents are marketed as providing convenience by acting on your behalf. But the trade-off is privacy and control. You’re handing over your personal information to a black box with little visibility into how it’s used. Multiple incidents are fueling a conversation about the dangers of agentic AI and whether they require higher security standards before being granted access to user data.

And given Meta’s track record of privacy fines, data sharing and security issues, it’s worth proceeding with caution. Earlier this month, a lifestyle blogger reported that the social media platform’s AI asked intrusive questions about her kids and pieced together private information about her life from her posts. Meta’s controversial smart glasses have received pushback on multiple fronts — from its facial recognition software to the way it captures and stores data.

Before facing a potential security nightmare, here’s what to know about Muse.

Muse uploads iOS or Mac data even when you tell it not to

Meta’s Muse appears to blatantly ignore user permissions, according to a report by AppleInsider. In one case, the AI agent synced roughly 187,000 lines of a user’s Apple Messages without their consent, even though “Full Disk Access” was turned off.

The report shows that Muse pinged a user’s messages database thousands of times despite disk access being disabled. Muse then successfully harvested texts from the user’s Mac — not from Meta’s Messenger, but from Apple Messages.

Even people who refuse to use Muse may have their data collected by the AI if they text someone who does have it installed.

Muse could hand over data to human callers

Before Meta launched the ability for its Muse to make outbound business calls on your behalf, internal Meta documents revealed that the company planned to rely on human contractors at call centers to help make reservations and appointments.

That means not only would the software have access to all your private data, but a total stranger might also be managing your personal commitments — all without your knowledge. The human concierge feature appears to have been rolled back for now, according to Reuters.

Muse has the most robust data collection

The VPN company Surfshark said it found that Meta Muse is collecting — or attempting to collect — 31 out of 35 types of data, putting it far ahead of other popular chatbots like Gemini, ChatGPT and DeepSeek. Muse also collects highly sensitive personal information like location data, sexual orientation, genetic information or biometric data.

Muse (along with Meta AI and Gemini) also reserves the right to use collected audio data for other purposes, such as analytics or product personalization. Surfshark released a full dataset for what it uncovered.

A representative for Meta did not immediately respond to a request for comment on the privacy concerns mentioned in this story.

Want to share your experience with Meta’s Muse or other AI agents? Email us at editors@cnet.com.

 

Click to Follow saysit.net on

THE BLAZE

The investigation into former special counsel Jack Smith has

KALIYADI Polarized Sunglasses
for Men and Women

NINTENDO LIFE

Image: Ollie Reynolds / Nintendo Life If it’s not

NASA NEWS

The four members of NASA’s SpaceX Crew-13 mission to