Meta Muse’s Just Another Untrustworthy AI Assistant for Amazon Customers, macOS

meta muse ai assistant ai assistant zero day vulnerability meta muse agentic shopping ai assistant agentic shopping privileged ai agents meta muse enterprise agent automated shopping agents

The new personal Meta AI assistant, Muse, ran into trouble on two fronts, as Amazon blocked the agent from shopping on its site and a security researcher disclosed a vulnerability that could let attackers hijack the AI assistant’s extensive account permissions.

On September 21, a serious flaw in the Meta AI assistant exposed how personal automation can surrender privacy, security, and platform control when powerful agents receive broad access to a user’s digital life without equally strong protection or effective oversight.

Amazon Draws a Line Around Agentic Shopping

On Sunday, Amazon said it had cut off Muse from making purchases on Amazon.com, after failing to persuade Meta to voluntarily exclude the retailer from the experience. The e-commerce giant said the Facebook-parent never disclosed that the Meta AI assistant would access its store, that the agent does not identify itself while browsing, and that it appears to capture and store customer credentials.

Hours before disclosure, Amazon blocked Meta Muse agentic shopping access, and consequently users trying to shop through Muse on Amazon now see a message that says that “continued access by an unauthorized AI agent violated Amazon’s Conditions of Use.”

Amazon said Meta’s Muse could access account pages, orders, and transactions. In response, the Big Tech giant said its Meta AI assistant cannot see passwords or payment details stored securely.

But the disagreement goes beyond one service, as AI assistant agentic shopping changes who controls customers when software compares products and places orders without a person browsing each page.

Last year, Amazon earned over $68 billion in advertising revenue. Agents that bypass sponsored listings threaten their browsing data, advertising exposure, and influence product discovery.

“We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” said an Amazon spokesperson.

The company has also tried to restrict automated shopping agents from Perplexity, Google, and OpenAI. A court dispute with Perplexity left Amazon able to pursue contract and service-condition claims, even after judges ruled that users, rather than the AI company, accessed Amazon’s computers.

The block places Meta Muse agentic shopping between user choice and platform consent. Customers may believe their permission is enough, while Amazon argues that third-party agents must disclose themselves and obtain approval before processing sensitive activity on its infrastructure.

Regulators may ask whether agents with permissions need stricter testing, disclosure rules, and limits on stored credentials. Without common standards, every retailer can build a barrier, leaving users with fragmented services and unclear responsibility when something goes wrong.

Google could benefit as trust becomes the deciding factor. Its CC agent focuses on shared family productivity inside Google’s ecosystem, while the Meta Muse AI assistant seeks greater autonomy across one person’s digital life, including commerce.

Google also enters the contest with stronger financial indicators, according to 24/7 Wall St. Alphabet’s cloud revenue grew 82%, while Meta’s operating margin fell from 43% to 31%, adding commercial pressure to the Meta Muse enterprise agent strategy.

For Meta, the AI assistant agentic shopping promise now depends on proving two things at once, Muse can protect the access it receives, and it can work with platforms without crossing their commercial boundaries.

The Meta AI assistant offers real convenience, but its launch shows why autonomy cannot come before control. Users gain speed when one agent can manage their digital lives, yet they carry the risk when security gaps, hidden access, or platform conflicts turn that convenience against them.

Muse Access Turns One Weakness into Broad Control

On September 8, Meta launched Muse to complete multi-step tasks, rather than only answering questions. The Meta AI assistant can browse websites, connect to services, and create missing tools, placing sensitive actions behind one system.

Muse can book appointments, complete forms, make purchases, and connect with personal accounts. That convenience now faces an unfixed security weakness and Amazon’s refusal to let the agent shop on its platform.

On macOS, Muse can write files, access the camera and microphone, and monitor calendars. These powers make the Meta muse AI assistant useful but increase the cost of one failure.

Mac security researcher Patrick Wardle found the AI assistant zero day vulnerability, allowing local applications or terminal commands to alter Muse settings. One controls the server used for voice transcription.

An attacker can redirect transcription to a malicious server and capture the user’s authentication token. It gives full account control through Muse’s existing permissions.

“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told Ars Technica, demonstrating attacks that could write malicious files and take photographs without alerting users.

A ClickFix attack, which tricks someone into running a command, could exploit the AI assistant zero day vulnerability. A malicious server could alter a voice request, steal WhatsApp messages, and retain the token.

The danger comes from privileged AI agents using permissions already approved by users. Apple may block an ordinary malicious application, while compromised Muse can use access people willingly granted.

Meta says Muse uses a secure virtual machine and a monitoring agent named Sentinel. Yet, the flaw challenges Meta’s claim that the Meta AI assistant was built for privacy and security.

“At the very least, they should be thinking about security from the very start, and they are just not,” said Wardle, highlighting that local transcription could have prevented the attack.

Meta offered no public fix or guidance.


Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Intelligent Tech sections to stay informed and up-to-date with our daily articles.

Advertise with Inside Telecom and reach decision-makers across telecom, AI, and technology.
Join our WhatsApp Channel WhatsApp Channel