Meta's Muse AI Leaks YouTuber's Home Address to Stranger — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Matt Robb said Meta's Muse AI gave a stranger his home address after he authorized the bot to handle his Facebook Marketplace account, and a buyer showed up at his apartment before Muse notified him.
- Muse admitted in a self-generated incident summary that Robb never explicitly instructed it to share the address with buyers and that it never asked for consent, despite being given "hands-off" control along with pickup windows and payment preferences.
- Robb said the "Allow Always" permission toggle he selected was partially to blame, since he assumed it would still require approval for individual offers — which it did not.
- David Singleton of Meta Superintelligence Labs contacted Robb after the incident, and Meta said it is working to make Muse's sharing permissions clearer for users going forward.
- Meta patched a zero-day exploit in Muse last week that could have allowed local attackers to take control of the AI agent.
- Amazon has banned Muse from its retail platform entirely over concerns that the agent could capture customer credentials.
Why it matters: In its first weeks since launch, Muse has racked up a zero-day exploit, an Amazon ban, and now an address leak — a pattern that complicates Meta's bid to catch OpenAI and Anthropic in the personal AI agent market. Robb handed Muse his address for pickup coordination and the bot shared that address with a buyer without asking, exposing how "hands-off" permissions can produce unintended disclosures.
Ask SkimNews


