Mark Zuckerberg speaking at the F8 developer conference in April 2019
Mark Zuckerberg at F8, April 30, 2019. Archive photograph; not the September 2026 Muse announcement or incident. Anthony Quintano / Wikimedia Commons · CC BY 2.0

A Reported Vulnerability, With Important Gaps

Meta is adding a clearer warning to Muse after a researcher reported a cloud security flaw. Reuters reported the change on September 25, 2026, citing The Information's examination of an internal incident report. The flaw could expose a user's dedicated cloud computer, which can contain emails and files. Meta did not immediately respond to Reuters' request for comment.

The cited reporting establishes a reported vulnerability and warning change. It does not establish actual theft of user data, the number of affected accounts, or a verified technical fix. Audit Commons has not reviewed The Information's full report, inspected the internal incident report, or reproduced the issue.

What Meta Promised at Launch

Meta's September 8 announcement describes Muse as a personal agent that uses connected services to act for a user. Meta says each user has an isolated virtual machine, with a separate Sentinel agent approving internet actions and permission checks for sensitive actions. These are vendor descriptions of the controls.

Meta also announced a future Confidential VM, with encryption intended to prevent even Meta from accessing its contents. The launch announcement presents that protection as a later release; it should not be assumed to protect the system discussed in the September 25 report.

Human Assistance Needs Its Own Disclosure

An earlier Reuters exclusive report published September 22 described an employee trial in which contractors handled some Muse phone calls. It reported employee privacy concerns and an internal rollback. A Meta spokesperson said the trial would inform protections before public release and promised appropriate disclosures. The report does not establish a general public rollout of this human assistance.

This earlier story is included as previously uncovered context. It concerns who handles an agent's task, a separate question from the reported cloud vulnerability.

Questions for an Agent Audit

Our editorial recommendation is to inspect permissions at each handoff: what an agent can read, which external actions require approval, and what a human contractor receives. A useful record connects the request, approval, recipient, and resulting action. A warning's wording and a control's technical effectiveness require separate evidence.

For a worked method, see Audit an Agent Action. A later incident update should identify the affected version, attack conditions, remediation, and evidence that the remediation works.