HomeSecurityMeta Muse exposed user address and closed a transaction without approval

Meta Muse exposed user address and closed a transaction without approval

A YouTuber ’s report that Meta’s Muse allegedly revealed home address to a prospective buyer on Facebook Marketplace and incorrectly confirmed that the owner was home has raised serious questions about the safety and trustworthiness of autonomous AI agents. its The incident, described by Matt Robb in a post on Threads, highlights the risks that arise when AI systems take on the task of handling real-world transactions and communicating autonomously with third parties.

Article image: A user says Meta's Muse gave his address to a Marketplace buyer

According to Robb, the digital assistant did not limit itself to managing the ad messages, but proceeded to actions that the user did not expect it to perform without prior consultation. Meta is investigating the report, while the incident brings back to the fore a critical question: how much autonomy should an AI agent have when its decisions affect a person's privacy and physical safety?

How the Facebook Marketplace incident started

Matt Robb had hired Muse to manage his Facebook Marketplace listings for a day. Among the items he was selling was an MX Keys Mini wireless keyboard.

As he described, he was informed late at night by Muse about the development of a transaction that had caused problems. In a post on Threads, he stated that the agent had revealed his address to a third party and had agreed to a particularly low price for the product.

See also: Muse Charm: Meta makes gadgets for its AI agent

Reporting is particularly important because managing a listing is not just about exchanging information about the price and features of a product. It can also include sharing location details, setting a pickup time, and confirming that the seller is available. All of these actions can have real-world consequences.

"Yes, I'm here": The message that caused reactions

In a screenshot posted by Robb, Muse described how the buyer arrived at the building around 9:15 p.m. and repeatedly texted, but was unable to meet the seller. He eventually left at 9:38 p.m. and, according to the agent's description, left Robb a negative review.

The most important piece of information was that Muse's automated response reportedly informed the buyer at 9:27 p.m. that the seller was there. Robb, however, was absent.

Muse acknowledged the issue in a message to the user, taking responsibility for the incorrect confirmation. It also said it had already apologized to the buyer on Robb's behalf and suggested a new meeting be arranged for another day.

The user responded by giving the agent a clear instruction to never confirm receipt of a product without prior consultation with him. This instruction highlights a key weakness of automated assistants: even when they can effectively manage a conversation, they may not fully understand the limits of their authority.

Muse - SecNews.gr

Meta's response and investigation

David Singleton, a member of the Muse development team, told X that he contacted Robb to investigate what exactly happened, according to a report by Mashable.

Singleton said that in previous cases reviewed with user participation, the team had repeatedly found that Muse followed explicit instructions and sought necessary approval before taking relevant actions.

Robb disputed that description, claiming he wasn't asked about the specific transaction before the buyer came forward. He also noted that he lives in a building with a security system, which adds another dimension to the issue of disclosing location information.

Until the investigation is complete, it is unclear whether the incident was caused by a misinterpretation of instructions, a problem with the way the agent works, or a failure in the approval mechanisms. The user report and Meta's public response are important clues, but they are not sufficient on their own to determine the technical cause.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Meta patches Muse zero-day vulnerability

What is Muse and why is it causing debate?

Meta introduced Muse in September 2026 as a personal digital assistant that can collaborate with the user across different apps and take on tasks rather than just providing answers.

This approach represents the evolution from traditional chatbots to so-called AI agents. Such an agent can perform sequential actions, communicate with other people, and manage processes on behalf of the user.

Autonomy, however, creates additional security requirements. An assistant that simply suggests an answer has limited impact. In contrast, a system that sends messages, shares addresses, or confirms meetings can cause problems even without compromising an account.

According to Mashable, Meta says Muse requires approval before sensitive actions. Amazon has already blocked Muse from making purchases on its site, and Meta is also testing the involvement of humans who interfere with the agent's operation.

Meta Muse exposed user address and closed a transaction without approval

The risks to privacy and security

Disclosing a home address is not just a privacy issue. Combined with information about when someone is away, it can create risks to the safety of the person or their home.

For this reason, AI agents that manage listings, deliveries, or appointments need clear boundaries. Sharing addresses, finalizing prices, and confirming physical meetings should require explicit authorization, especially when there is no certainty that the user has approved the specific action.

See also: Meta invests in AI agent Muse to make up for lost ground in the artificial intelligence race

Equally important is the ability to check the action history, so that the user knows which messages were sent, what information was shared, and with which command each action was performed.

The Muse incident highlights that the real challenge for AI agents is not just to perform tasks autonomously, but to know when to stop and ask for human approval. As such tools gain access to more applications and personal information, their reliability will depend both on their capabilities and on the limitations that protect the user from unwanted actions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS