Meta has fixed a security vulnerability in Muse that might have allowed an attacker to get inside the virtual machine assigned to an individual user, Reuters reported in a story carried by ETCISO on 25 September. The flaw was found by a researcher and reported through Meta's bug bounty programme. Meta classed it as SEV-2, the second-highest rating on its severity scale.
The stakes are set by how Muse is built. Every account is given a Muse Secure VM, a cloud machine that runs the agent and keeps copies of whatever emails and files the user connects. A way into that machine would therefore be a way into much of the user's digital life, or at least the parts they had linked to the agent.
Meta also used the fix as an occasion to make the Muse app's safety warnings clearer. The report did not say whether the flaw had been exploited. The disclosure came in a difficult month for the agent, which had already lost access to Amazon's store and, three days later, was reported to have shared a user's home address.
Update the Muse app and pay attention to its warnings. Connect an account only when a task you are running actually needs it, because each one adds to what a single flaw could reveal.