A security researcher has demonstrated a working zero-day vulnerability capable of hijacking Meta Muse, raising fresh questions about how ready the assistant is to handle real accounts and money. The flaw circumvents safeguards Meta built into the product just weeks after its public launch.
Muse launched on September 8 as Meta’s autonomous personal assistant, able to send emails, book travel, fill out forms and complete purchases on a user’s behalf. The agent is built on the Muse Spark 1.3 model under chief AI officer Alexandr Wang and runs inside a dedicated cloud-based virtual machine Meta calls the Muse Secure VM, an architecture designed to isolate each user’s agent and data.
Meta Muse Security Design
Meta paired each Muse instance with an oversight system named Sentinel, which Meta describes as the sole permission authority over connected services and all outbound internet traffic. Sentinel swaps in surrogate tokens at the network boundary so the agent never sees actual passwords or payment details. Meta has also said that any critical approval, such as sending money or confirming a purchase, is surfaced to the user through the app rather than being granted autonomously by Muse.
Exploit Details and ClickFix Technique
The researcher used a ClickFix-style technique — a social engineering method that tricks a user or automated system into running a malicious command disguised as a routine fix or verification step. The method exploits Muse’s ability to browse the web and follow instructions found on a page, a known weak point Meta has publicly acknowledged. Meta’s own security documentation states Muse is not immune to attack and that prompt injection remains an open problem across the AI industry.
Bounty Program and Public Positioning
Mark Zuckerberg has promoted Muse as a step toward a personal superintelligence to help people manage their digital lives. Meta opened a public bug bounty program with rewards up to $300,000 for validated vulnerabilities and set aside a specific $130,000 reward for anyone who can demonstrate a prompt injection attack against the system. That bounty structure indicates Meta anticipated researchers would test for this class of flaw.
Meta’s documentation and the demonstrated exploit together underline that, despite isolation measures and oversight systems, prompt injection and web-borne instruction handling remain practical attack vectors for Muse.

