Is Meta Muse Safe? Connectors and Permissions

Last reviewed . Every claim below is backed by a source in Sources. Where we have no source, the guide says so.

Meta has published a detailed account of how Muse protects connected accounts, and in it Meta says plainly that “Muse isn’t immune to attack.” By Meta's account, the model never sees your passwords or keys, each connector has its own permission settings, and Muse asks before it sends an email or makes a purchase. One public flaw, in the Mac app, was hotfixed in September. Nobody outside Meta has published an independent audit that we have found. This page sets out what Meta says, what has gone wrong in public, what users report, and which settings are yours to choose.

What Muse can and cannot see

All of this is Meta describing its own design.

The permissions you set

Access is chosen per connector, not all at once. The launch post: “For things like email, people choose what Muse can do, whether it reads their mail or can also send on their behalf.” Meta's help page on connectors adds that “Many Connectors can also be set up so that Muse is only able to retrieve data, but not take actions”, and that disconnecting “stops Muse from exchanging data with the Connector.”

Meta's help page on approvals lists two levels. With Ask for some actions, Muse “will ask for permission before every write action and important read actions”; Always ask covers any action. When it does ask, the answers are Allow once, Allow for this task, Allow for this site, Always allow and Deny. The same page says: “Because Muse acts on your behalf, you're responsible for guiding it carefully and approving its actions.”

Partners describe the same split on their side. Dropbox says actions that change your content “will prompt Muse to request additional confirmation”, and that “Connecting Muse does not change your existing Dropbox sharing settings.” Tailscale posted that “your existing Tailscale access controls still decide what it can reach” (@Tailscale, 1 October).

Payments

Meta's safety write-up says that on a site where your card is already saved, Muse asks for approval “with the exact details of the purchase every time.” Through its wallet, “a single-use card number is issued”, tied to one merchant, one amount and a limited time. At launch that wallet was Link by Stripe; Shop Pay has since been added.

What has gone wrong in public

The Mac dictation flaw, September. Security researcher Patrick Wardle found that “any app or Terminal command running locally on a Mac can change a number of undocumented Muse settings”, one of which redirected dictated prompts so an attacker could grab the account's token, according to 9to5Mac. The Verge reported on 22 September that Meta patched it within hours of Ars Technica's report, and quoted David Singleton of Meta Superintelligence Labs: “This was a local privilege escalation attack, not a remote exploit” and “we have issued a hotfix to the app to address the issue.” Wardle's reply, quoted by 9to5Mac, was that “a simple ClickFix attack could deliver the hijack” remotely. 9to5Mac's advice: “If you use Muse on Mac, update ASAP.”

Before launch. On 5 October 404 Media reported, citing an unnamed Meta source and internal posts, that engineers fixed several vulnerabilities in the weeks before launch, at least one of which could have let a user break out of Muse's virtual machine. Meta's statement to 404 Media said Muse was strengthened “through extensive dogfooding, agentic red teaming and our bug bounty program — and that work continues.” We have no source showing that flaw was used against anyone.

Amazon's objection. Amazon told GeekWire that Muse appeared to capture and store customer credentials. Meta's own description of credential handling is above. Both sides are set out in our Amazon guide.

What users report

Saved posts, quoted word for word. They are single accounts, not tests we ran.

Custom connectors are a different case

Meta's connectors help page says “Meta doesn't review custom connectors or how they use your information, so grant access with caution.” What that means in practice is in our custom connector guide.

Settings worth checking

Each of these is a control Meta or a partner describes, not advice of our own about risk.

What is not published

Sources

Something here wrong or out of date? Tell us and we will fix it.