It was a two-sided week for Muse, Meta's new AI assistant. On one side, the app is growing faster than ChatGPT did in its first days on mobile. On the other, Amazon blocked Muse from shopping on its site, and a well-known macOS security researcher published a flaw that lets an unprivileged local process take over the agent.

The growth numbers

According to estimates Apptopia gave TechCrunch, Muse beat ChatGPT's downloads over the same first 12 days. To keep the comparison fair, only iOS data for the US and Canada was used: 1.8 million downloads for Muse against 1.3 million for ChatGPT. Globally, Muse was installed 2.8 million times in its first 12 days. Its US daily active users stand at 642,000; ChatGPT had 231,000 at the same point. The app has climbed to No. 1 on the US App Store.

The Amazon block

On Sunday night, Muse users trying to buy goods on Amazon hit an error message. It said that "continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." GeekWire spotted it first.

TechCrunch notes it is easy to read this as a rivalry between giants: Amazon has its own models and one of the biggest inference platforms. But there may be a simpler reason. If Muse places a bad order, Amazon is the one left dealing with both the angry customer and the angry seller. Muse has one of the lower hallucination rates among models, but it is not zero.

The macOS flaw

The more serious news is on the security side. Patrick Wardle, a researcher who focuses on macOS security, found a zero-day in Muse's macOS app and published a proof of concept called "not-a-mused". His findings:

  • The app has an undocumented setting: endo_voyager_dictation_endpoint.
  • An ordinary local process without elevated privileges can change it.
  • Once changed, Muse's dictation traffic, meaning voice commands and prompts, goes to an attacker's server.
  • That lets an attacker read prompts, inject their own instructions and steal authentication tokens.

Exploiting it requires code already running on the machine; it cannot be triggered directly from afar. But as Ars Technica points out, no sophisticated attack is needed: a ClickFix-style lure that tricks the user into pasting a single terminal command from a fake verification page is enough.

Wardle explains it with an apartment analogy: "Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments." With Muse, anyone who gets into the building can inherit every permission the user has given the agent. AI apps, he says, "have so much access if you configure them to be useful. They basically could do anything on your computer," which turns them into a single point of failure against the operating system's security controls.

Meta had not commented on the flaw at the time of reporting, and there is no word on a patch.

What it means for users

For anyone running Muse on macOS, the most concrete step is never to paste a command from a web page into Terminal. No legitimate verification step asks for that. The broader lesson: giving an agent access to email, calendar, files or shopping means any flaw in that agent reaches all of them too. When granting permissions, separate what is useful from what is necessary.