Meta Muse: 2.8 Million Downloads and Two Security Flaws
Published October 4, 2026
Meta Muse launched September 8, 2026 and became the top AI app in the US. In the same two weeks, one zero-day was patched and another flaw was downgraded.

Meta launched Muse on September 8, 2026, two weeks after an $18 billion settlement. Apptopia counted 2.8 million downloads in the first 12 days. Sensor Tower counted more than 3.4 million by September 25. Two security incidents surfaced in the same period. One of them was a zero-day patched about 12 hours after the story appeared.
What Meta Muse is
Muse is a personal agent from Meta. The difference from an ordinary chatbot sits in how it works. Meta says it can send email, book travel, fill in forms, negotiate on someone's behalf, and complete purchases. The app runs on iOS, Android, and muse.ai. Meta also opened it through WhatsApp, and promised smart glasses support in the near future.
The pricing has three tiers: free, Power, and Maximum. Power costs 20 dollars a month. Maximum costs 100 dollars a month. Signup asks for a card from the start. A usage meter shows remaining quota, including a warning before usage falls into a paid tier. The app was only available in the United States at launch.
Meta says the model behind it is the Muse Spark family. The internal code name for the product is Hatch. One outlet also reported a weekly token limit of 500 million for Power and 3 billion for Maximum. Meta has not confirmed those figures.
Architecture: one VM per user and a guard agent
The most disputed part is the workplace of Muse. Every user gets a dedicated virtual machine in the cloud. That machine holds the agent along with the user's data, including email and files from connected services. The environment also holds a separate monitoring agent that checks outgoing internet access. That agent asks for approval before sensitive actions run.
Meta's claim is that the environment is isolated. Meta also states it never sees the actual passwords or payment details. Meta opened a public bug bounty with rewards up to 300,000 dollars. That includes 130,000 dollars for a successful prompt injection attack that affects a single user.
One promise is still outstanding. Meta promised to build a Muse Confidential VM that stays encrypted even from Meta itself. That feature is not available at the time of writing.
Numbers that do not agree
Several parties reported the download count for Muse, and they do not match. The table below keeps each figure with its source.
| Source | Figure | Period |
|---|---|---|
| Apptopia | 2.8 million downloads | first 12 days |
| Sensor Tower | 2.8 million downloads | first two weeks |
| Appfigures | 1.1 million downloads | first 11 days |
| Sensor Tower | more than 3.4 million downloads | through September 25 |
The gap between the highest and lowest figure is roughly twofold. The reason is method. Apptopia counts downloads from outside the App Store and Google Play. Sensor Tower also counts installations from other sources. Appfigures relies on a model built from download patterns.
Appfigures also put net revenue at about 27,000 dollars from 1.1 million downloads. That works out to roughly two and a half cents per download. The figure matters because it shows that most users took the free tier.
On daily growth, Sensor Tower recorded a jump of 55 percent in the first days. For comparison, ChatGPT grew 24 percent in its first ten days. Claude reached 400,000 downloads and Grok 200,000 over comparable windows. By September 25, Muse had passed 3.4 million.
Who actually uses Muse
The data does not show large numbers of people using the agent for daily work.
Most users took the free tier.
Average revenue per download is about two and a half cents.
That figure does not match the picture painted about the future of work.
One pattern is worth reading. A first download spike usually contains people who want to see the new thing.
Continued daily use is visible only among a small minority.
Most products of this kind have shown the same curve.
Two security incidents in two weeks
The first incident was reported by WIRED on September 23, 2026. The finder was Patrick Wardle, a macOS security researcher. Wardle found a local flaw in the Muse app on macOS. It let any app already installed on the machine change a list of undocumented endpoints. Those endpoints included the place where the transcription process runs. Redirecting that endpoint sent the account token to an attacker's server, which gave full control of the Muse account. Wardle also built proof of concept cases, including writing files and taking screenshots without any indication to the user.
Meta patched the flaw about 12 hours after the story appeared. Meta stated the flaw was not a remote exploit, because it required a compromised device or an app that was already installed.
The second incident was reported by The Information on September 25, 2026, based on an internal Meta incident report. An external researcher found a flaw that let an attacker reach another user's virtual machine, including email and files. The path started when a user gave Muse a link to a malicious page to summarise. When a warning appeared, the user pressed Allow. The flaw let an open VM be reached from outside the per-user boundary.
Meta initially rated it SEV-2, the third of five levels in its internal bug scoring. A few days later, Meta said the first rating was wrong and lowered it to SEV-3. Meta responded by enlarging the warning, strengthening VM isolation, and adding a monitoring agent.
Analysis: why a flaw in the VM means other people's data leaks
The two incidents look very different, yet both start from the same thing: the access boundary. In an architecture like Muse, one user runs one virtual machine, so one person's data ends up in one place. The table below shows what is already exposed and what is still closed.
| Area | What can touch it | What closes it |
|---|---|---|
| Account token | Any local app | Meta patch, 12 hours after the report |
| Another user's VM | A malicious page plus one approval | Warning, VM isolation, monitoring agent |
| Contents of user files | Agent commands on its own VM | Model behaviour only |
| Passwords and cards | Meta's claim that it never sees them | No encrypted VM yet |
The first two rows point to two different kinds of problem. The first flaw sits on the user's own device, so the risk stays with one account. The second flaw sits at the boundary between users, so one mistake on one side can carry another person's data with it.
There is one pattern linking both. They both rely on a value treated as trustworthy, then use it without a wide enough limit. In the first case, the transcription endpoint was considered safe because the app used it itself. In the second case, a warning was considered enough because it had an Allow button. Neither is a model failure. Both are failures in the layer that grants permission.
The Linux system inside the VM is not the cause on its own. What matters is the decision about who may use that endpoint.
Two other details are worth reading. Amazon blocked Muse from its site for a period, and the reason was never explained. That kind of access cutoff shows that a security problem does not stop at the vendor's own servers. Third-party sites become part of the attack surface.
One more report deserves a place here. A researcher asked Muse to archive the files it could see and send them to Google Drive. Muse ran the request. The archive was large, and it appeared to hold system files, internal documents, agent logs, and SSH keys. Meta labelled the report Not Applicable. The researcher stated he did not try to escape the container boundary.
That report matters because it answers the wrong question. The real question is not whether an agent can read everything on a machine. The question is whether that content is placed in one machine in the first place.
What changed after the two incidents
Meta did not stop at two patches. Other changes followed.
First, the warning grew. The Allow button originally appeared with one short sentence. After the second incident, the warning became longer and names the action being permitted.
Second, incident details were published. Meta shared a technical summary and a short timeline. Few large companies do that.
Third, the bounty programme opened wider. A bug bounty that was previously internal now takes reports from outside researchers.
Fourth, there is an admission that the limits are unfinished. Meta states that several features are still in a limited stage, and the admission appears in the documentation rather than on the launch stage.
Hardware form and launch context
One rarely mentioned detail is the hardware.
At a Meta event in the third week of September, Zuckerberg demonstrated a handheld device called Muse Charm.
The device was described as a digital pet.
The goal is simple: the app can be used without a phone.
Price and availability in Europe have not been announced.
One more piece of context is worth noting. The launch came two weeks after Meta settled $18 billion with a group of plaintiffs.
What is still unclear
One large question hangs in the air: whether the zero-day was ever used by an attacker. Meta gave no answer, and no user data leak has been reported from it.
The second question concerns the monitoring agent. The feature exists, but the limits of what it can do have not been explained technically.
The third question concerns the Confidential VM. That encryption promise is still a plan.
The fourth question is about the download figures. Trackers disagree widely, and Meta has never confirmed which one is right.
The fifth question concerns availability. The app is still locked to the United States, with no date for Indonesia or other regions.
For readers in Indonesia
Muse cannot be used here yet, so the pattern is the useful part.
The first pattern is the agent workspace. Email, calendar, and document data are placed together in one computing environment. In Indonesia, the same pattern appears when a digital wallet and QRIS are connected to a third-party service.
The second pattern is the approval button. Both incidents above end in one click that was approved too quickly.
The third pattern is severity classification. Lowering a SEV level means less resources for a fix.
These questions are useful at any time:
- Where is my data actually stored, and who can read it?
- Is there an environment encrypted even against the service provider itself?
- Is there a list of actions that always come back to a human?
- Can I read the agent's action log?
- Can one mistake reach another user's data?
The pitch sounds big: an agent that handles everything on its own. The value is real because repetitive work can shrink. But the first two weeks showed that the security boundary decides whether the feature can really be used.
Related tools
Free browser tools that apply to this topic.
- Password GeneratorCreate random passwords in your browser.
- Password Strength CheckerSee what a password gives away, in your browser.
- AI Writing TellsFind generic patterns in your own writing. Not an AI detector.
- AI Text HumanizerRewrite text into more natural, readable language while preserving its meaning.
Share this article
Share to
Related articles

October 3, 2026
Dots: The Four Permission Layers Behind Always-On AI Agents
Dots runs around the clock on a cloud computer. OpenAI's four permission layers show which operations may proceed alone, and which must go back to a human.

October 1, 2026
AI Slop: The Word That Named the Content Glut
In 2025, one four-letter word won the word-of-the-year vote. Not for being trendy, but because of the cheap content flooding the internet.

October 1, 2026
Why AI Misreads Long Documents, and What Actually Fixes It
A pattern repeats across models: accuracy peaks when the relevant information sits at the start or end of a document, and collapses in the middle.



