Meta downgraded a Muse security flaw from SEV-2 to SEV-3, then built a secure VM anyway
A second, distinct Muse security disclosure surfaced this week, separate from the filesystem-export design choice Pondero covered on September 27: an external researcher, reporting through Meta's bug bounty program, found a flaw that could have let an attacker reach a user's dedicated Muse virtual machine, the individualized cloud account holding that user's emails and files, according to an internal Meta incident report reported by Reuters on September 25, 2026.
What happened
Meta initially classified the flaw as SEV-2, its third-highest severity rating on a five-point scale, before downgrading it to SEV-3 after determining the original assessment was incorrect, per BigGo Finance's report on the same incident. Exploiting it required a user to hand Muse a malicious webpage link to summarize or interact with, then click "Allow" on the security prompt that followed. Muse launched September 8 and reached roughly 2.8 million downloads in its first two weeks, Sensor Tower estimated, per Reuters. Meta did not immediately respond to Reuters' request for comment.
Meta added a secure VM and an approval gate, not just a warning
The severity downgrade did not translate into a light response. Meta made the security prompt more prominent, built a user-isolated Muse Secure VM, and deployed a monitoring agent that verifies Muse's external internet access and requires user approval before the agent takes sensitive actions such as sending emails or making purchases, per BigGo Finance. That gives anyone routing real tasks through Muse, email, travel, payments, a concrete new checkpoint: the "Allow" prompt that appears when Muse wants to reach an unfamiliar site is now backstopped by an isolation layer, not just a label. Operators who click through such prompts without reading them are the exact failure mode this flaw exploited.
This is the second Muse security story of the week but a different flaw than the one Pondero reported September 27, where Muse exported its own filesystem to a prompt and Meta called that behavior intended rather than a bug. That earlier issue was a design decision Meta chose to keep; this one was a severity-classified vulnerability Meta patched around.
What to watch next
Whether Meta discloses further bug-bounty findings as the Muse program scales, and whether two distinct VM-isolation and access-control issues in one launch month draws scrutiny from regulators evaluating how consumer AI agents handle account credentials and personal data.
Sources
- Meta bolsters Muse safety warning after security vulnerability found, The Information reports: Reuters, syndicating The Information, September 25, 2026
- Meta Hardens Muse Security After Bug Exposed User Emails and Files: BigGo Finance
