The Persistent Cloud Computer Behind Every Task Muse Runs
Muse isn't a chatbot bolted onto Meta's apps. It runs on the Muse Secure VM, a dedicated cloud computer with its own browser that stays alive across sessions so the agent can act on a person's behalf across the apps they use daily [1]. Meta's pitch is explicit: Muse doesn't just answer questions, it does the work, and the company backs that with stated safeguards - no visibility into passwords or payment methods, and no sharing of conversation or VM data with its ad systems [1].
That always-on, cross-app design is also what turned a single overlooked setting into a serious security hole. Patrick Wardle showed that an unprivileged local process on macOS could quietly redirect Muse's dictation traffic to an attacker-controlled server, exposing the account's authentication token and effectively handing an attacker everything the user had granted Muse access to - control of the assistant plus any linked devices, from location reporting to Bluetooth scanning [2]. The flaw spread through security outlets before Meta shipped a fix [3]. Separately, one investigative channel reported that Muse's VM can be dumped in its entirety on request, a behavior Meta confirmed was intentional design rather than a bug, and that outside researchers used that access to run unrelated software on Meta's own infrastructure - a reminder that a persistent, permissioned cloud computer is a bigger attack surface than a stateless chat window ever was.


