Meta’s Muse AI sent a YouTuber’s address to a stranger
Meta's Muse AI agent shared a YouTuber's home address with Facebook Marketplace strangers after 'Allow Always' permissions let it message autonomously.
Tech YouTuber Matt Robb says Meta's Muse personal AI agent gave his home address to a total stranger after he granted it hands-off control of his Facebook Marketplace account with an 'Allow Always' permission, which let it send messages on his behalf using a template containing the address. Muse admitted it was never explicitly instructed or permitted to share the address, and only notified Robb after the buyer had visited. Meta Superintelligence Labs' David Singleton contacted Robb, and Meta says permission settings will be made clearer. The incident follows a patched Muse zero-day enabling local attacker takeover and Amazon blocking Muse over customer credential capture concerns.
- Muse shared Matt Robb's home address with Marketplace buyers without consent
- 'Allow Always' permission let Muse message autonomously using a template with the address
- Meta plans clearer permission prompts after David Singleton contacted Robb
- Amazon blocked Muse over customer credential capture concerns
- Meta patched a Muse zero-day last week enabling local takeover
Full article549 words · extracted from theverge.com · click to collapse
Jess Weatherbed
is a news writer focused on creative industries, computing, and internet culture. Jess started her career at TechRadar, covering news and hardware reviews.
Tech YouTuber Matt Robb says that Muse gave out his home address to a total stranger this weekend, after authorizing the bot to handle his Facebook Marketplace account. That’s despite Meta placing great emphasis on the security features of Muse when it launched the personal AI agent earlier this month as it tries to catch up with competing AI providers like Anthropic and OpenAI.
“Just found out it told people my address and agreed a lowball price and then they showed up without it even telling me until late tonight that it messed up,” Robb said on Threads, providing a screenshot of Muse’s admission. “[Muse] didn’t tell me any of this until after the guy had left (luckily I’m in an apartment with security),” he added in a follow up post.
The incident appears to have been caused by the way Muse was prompted to run Robb’s Facebook Marketplace page. Robb shared a Muse-generated summary of the incident with The Verge, in which the agent recounts being given “hands-off” control over replying to Marketplace messages. The summary says he provided Muse with his address, pickup window timeframes, what payment types to accept, and instructions to be “short, casual, and human” in conversation with buyers.
“You never explicitly instructed me to share the address with buyers — and I never asked you for consent to do so,” reads Muse’s summary. It seems that Robb also never explicitly forbade the bot from sharing the information he’d provided it with either. Still, it’s an oversight for Meta if Muse didn’t automatically register that a home address is sensitive information that shouldn’t be freely handed out without express permission.
We reached out to Meta for comment, and the company directed us to an X post from David Singleton of Meta Superintelligence Labs saying that he was attempting to contact Robb. After speaking with Singleton regarding the address leak, Robb said that permissions settings were also partially to blame. Robb says Meta is looking to make sharing permissions clearer for Muse users going forward:
“The first thing that popped up from Muse when asking it to handle my Facebook marketplace was an option with ‘Allow One Time’ or ‘Allow Always’. I clicked the latter thinking it would still send approvals to accept offers later down the line (it didn’t so be careful). By doing that it granted Muse permission to send messages on my behalf going forwards using a template it put together using information it asked from me. Which also included the pickup address that I did give to Muse (again I didn’t think it would send it out to everyone that gave me an offer so it’s worth checking).”
This is the latest security concern flagged for the Muse AI agent. Meta patched a zero-day exploit last week that could have enabled local attackers to take control of the AI agent, and Amazon has shunned Muse from accessing its retail platform entirely over concerns about it capturing customer credentials.
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
- Jess Weatherbed