Tech YouTuber Matt Robb says that Muse gave out his home address to a total stranger this weekend, after authorizing the bot to handle his Facebook Marketplace account. That’s despite Meta placing great emphasis on the security features of Muse when it launched the personal AI agent earlier this month as it tries to catch up with competing AI providers like Anthropic and OpenAI.

“Just found out it told people my address and agreed a lowball price and then they showed up without it even telling me until late tonight that it messed up,” Robb said on Threads, providing a screenshot of Muse’s admission. “[Muse] didn’t tell me any of this until after the guy had left (luckily I’m in an apartment with security),” he added in a follow up post.

The incident appears to have been caused by the way Muse was prompted to run Robb’s Facebook Marketplace page. Robb shared a Muse-generated summary of the incident with The Verge, in which the agent recounts being given “hands-off” control over replying to Marketplace messages. The summary says he provided Muse with his address, pickup window timeframes, what payment types to accept, and instructions to be “short, casual, and human” in conversation with buyers.

“You never explicitly instructed me to share the address with buyers — and I never asked you for consent to do so,” reads Muse’s summary. It seems that Robb also never explicitly forbade the bot from sharing the information he’d provided it with either. Still, it’s an oversight for Meta if Muse didn’t automatically register that a home address is sensitive information that shouldn’t be freely handed out without express permission.

We reached out to Meta for comment, and the company directed us to an X post from David Singleton of Meta Superintelligence Labs saying that he was attempting to contact Robb. After speaking with Singleton regarding the address leak, Robb said that permissions settings were also partially to blame. Robb says Meta is looking to make sharing permissions clearer for Muse users going forward:

“The first thing that popped up from Muse when asking it to handle my Facebook marketplace was an option with ‘Allow One Time’ or ‘Allow Always’. I clicked the latter thinking it would still send approvals to accept offers later down the line (it didn’t so be careful). By doing that it granted Muse permission to send messages on my behalf going forwards using a template it put together using information it asked from me. Which also included the pickup address that I did give to Muse (again I didn’t think it would send it out to everyone that gave me an offer so it’s worth checking).”

This is the latest security concern flagged for the Muse AI agent. Meta patched a zero-day exploit last week that could have enabled local attackers to take control of the AI agent, and Amazon has shunned Muse from accessing its retail platform entirely over concerns about it capturing customer credentials.

Read the full article here

Share.
Leave A Reply

Exit mobile version