Amazon blocks Meta's Muse agent amid disputed macOS flaw
Amazon blocked Meta's Muse shopping agent over unauthorized access; sources split on whether a patched macOS token flaw was the reason.
Amazon began blocking Meta's Muse AI shopping agent on Sept. 21, 2026, showing users a message that continued access by an unauthorized AI agent violates Amazon's Conditions of Use. An Amazon spokesperson said third-party agents should identify themselves and respect service providers' decisions, citing privacy concerns because Muse does not identify itself and appears to capture customer credentials; Meta, which launched Muse earlier that month without an agreement, said it cannot see secure login or card payment details, while The Verge noted later reports that Muse could read user messages without the required permission. Sources disagree on why Amazon acted: Ars Technica tied the block to a serious zero-day, whereas The Verge, The Decoder, TechCrunch, and WIRED described unauthorized shopping and data handling, WIRED called the block separate from the flaw, and a Forbes account discussed on Hacker News reported no vulnerability identifiers or confirmed security incident. Patrick Wardle disclosed a macOS zero-day in which any local app or terminal command, regardless of permissions, could redirect Muse's cloud transcription endpoint and expose a token granting control of the Muse account, including prompt manipulation, file writes, and camera access with no user indication; Meta shipped a hotfix about 12 hours later. The clash sits in a wider fight over AI shopping agents that has also involved Perplexity, Google, and OpenAI: Amazon previously sued Perplexity over its Comet agent, a judge sided with Perplexity in August, and Amazon has removed details from order confirmation emails since July. TechCrunch added that mistaken agent orders could leave Amazon mediating customer and vendor disputes, and described Muse's hallucination rate as relatively low but not zero.
- On Sept. 21, 2026, Amazon blocked Meta's Muse from shopping on Amazon.com and told users that continued access by an unauthorized AI agent violates Amazon's Conditions of Use.
- Amazon said Meta had not notified it, that Muse does not identify itself, and that it appears to capture customer credentials; Meta said Muse cannot see secure login or card payment details.
- The Verge said later reports found Muse could read user messages without the necessary permission enabled.
- Ars Technica said Amazon blocked Muse because of a zero-day; WIRED said the block was separate, and a Forbes report discussed on Hacker News cited no vulnerability IDs or confirmed incident.
- Patrick Wardle disclosed a macOS zero-day: any local app or terminal command, regardless of macOS permissions, could redirect Muse's transcription endpoint and expose an account-control token.
- That token was reported to allow control across WhatsApp, email, calendar, and social accounts, plus prompt manipulation, file writes, and silent camera access.
- Meta released a hotfix about 12 hours after disclosure; WIRED said cloud dictation, rather than on-device processing, enabled the flaw.
- Amazon earlier sued Perplexity over Comet shopping access, a judge sided with Perplexity in August, and Amazon has stripped order-confirmation email details since July.
Coverage timelineoldest first · each row is one article
- · 5d agoAmazon doesn’t trust Meta’s Muse AI agent
The Verge · AI· 50
Amazon blocked Meta's Muse AI shopping agent, citing unauthorized access and privacy concerns over the agent failing to identify itself and capturing credentials.
- · 5d agoAmazon blocks Meta's AI agent Muse from online shopping
The Decoder· 55
Amazon blocks Meta's Muse AI agent from its platform over security concerns and unauthorized data handling.
- · 5d agoAmazon blocks Meta’s new Muse AI agent from shopping on amazon.com
Hacker News · AI· 44