Each Muse account runs on its own Muse Secure VM, a cloud machine holding the agent together with copies of the data a user connects. Reuters, in a story carried by ETCISO on 25 September, reported that a researcher had found a vulnerability that could have given an attacker access to one of those machines. The report came in through Meta's bug bounty programme.
Meta graded the issue SEV-2, one step below its top severity level. The seriousness comes from concentration: a machine that gathers a user's mail and documents in one place turns a single flaw into a potential window on all of them. The more accounts a user links, the more a breach of that one machine would reveal.
Meta fixed the flaw and made the safety warnings inside the Muse app clearer. The sources do not say whether anyone exploited the vulnerability before the fix, or how long it had been present.
Who was affected
Muse users with connected emails and files
The lesson: Whatever you connect to a cloud agent is copied somewhere you cannot inspect. Connect sensitive accounts for the duration of a task and no longer, and keep the app updated.