Meta Expands Muse AI Across Glasses and Charm as Security Questions Mount
Meta is expanding its Muse AI agent to smart glasses and a new Charm wearable after strong early adoption, while developers and researchers question Muse's security and its resemblance to OpenClaw.
Meta shares rose about 4 percent on Thursday to roughly $773 apiece, CNBC reported, as investors responded to the product and strategy presentation. The stock had been below $600 a month earlier and was moving back toward its August 2025 record close of $790. CNBC reported that the keynote delivered what it considered a combination of products, pricing and privacy.
At the event, Zuckerberg announced an expanded smart glasses lineup with new styles and a camera-free option. Some models will include an FDA-cleared over-the-counter hearing aid feature, CNBC reported. Meta also introduced a new pair of virtual reality glasses starting at $1,299, compared with the $3,699 Apple Vision Pro that Zuckerberg named during the presentation. The Muse Charm, a keychain device described as Tamagotchi-like, is still in testing but expected by the end of the year, Zuckerberg said. The Verge reported that Meta has named its Muse mascot Jolly and placed life-size paper cutouts around its campus. Meta CTO Andrew Bosworth showed his own Muse agent, Cooper, during the keynote.
In a demo, The Verge reported, an audio-only Muse agent named Henry took about a minute to identify a beef jerky stick as the best protein-for-calorie snack among several options, and later failed to add granola bites to a shopping cart because the product "did not exist in the catalog." The Verge said the demo showed both the promise of using smart glasses to get contextual AI help and the familiar limits of AI agents. Meta is adding more connectors to Muse. After earlier partnerships with Shopify and Expedia, Meta announced Walmart, Best Buy and Gap as new partners, CNBC reported. Amazon is blocking Muse from its marketplace.
Analysts at Morgan Stanley wrote in a note to clients that Meta's ability to extend connectors is important for removing friction in shopping and purchasing, and that it could unlock a $30 trillion consumer agentic spending market, according to CNBC. JPMorgan raised its price target on Meta to $920 from $820 and reiterated an overweight rating. The firm wrote that it expects Muse adoption and engagement to continue to ramp as Meta proves out AI returns beyond advertising.
Security researchers and developers have raised questions about Muse. Peter James and Jonny L. Saunders said they independently coaxed Muse into zipping and sharing the entire contents of its root filesystem, Ubuntu system files, app templates and internal documentation, The Verge reported. Saunders posted on Mastodon that it was "extremely easy" to replicate James's results and that Muse had "Almost no prompt injection resistance." Meta spokesperson Daniel Roberts denied that the incident was a security breach. He said Muse runs in persistent Linux virtual machines for each user, and that, "Just like with the laptop in front of you, of course you can see the files." Exporting virtual machine data does not give people privileged access to Meta infrastructure or other people's data, Roberts said.
The disclosure was the second Muse vulnerability reported this week. Security researcher Patrick Wardle found an exploit that could let attackers hijack the AI agent, redirect transcription processing and access a user's Muse account, according to The Verge. Meta issued a hotfix. The Verge also reported that when its reporter asked Muse to share its filesystem, it initially refused and called it a security risk. After starting a new session and using flattery and curiosity, the reporter said, Muse created "safe" versions of /opt/hatch and /home/hatch stripped of items such as SSH keys, exposed its full directory tree and offered to pull a safe copy of "any specific subtree that looks interesting." Roberts said Meta is continuing to update the product, so users may see changes in how much information is available about their virtual machine.
The files obtained by the developers describe how Hatch, Meta's internal name for Muse, processes requests, handles data and connects to services such as Gmail, The Verge reported. Muse stores its memory in plain Markdown files, and it performs a nightly "dream" review of recent conversations that it builds into guidance for future conversations, according to James. Saunders found that many Muse capabilities were hard-coded, including the ability to cancel subscriptions and the machinery that manages runaway agent spawning. Saunders speculated that many of the bash and Python scripts running Muse in the background were created using Claude, though that is unconfirmed. James also found references to a hardware integration called Meta Home Link, which appears to give Muse access to devices on a home network. Meta has not announced a feature by that name, and it may not ship.
Some social media users have alleged over the past week that Muse is directly built on OpenClaw, The Verge reported. The platforms use the same names for core files such as SOUL.md, memory and tools, and have similar lines in the document governing personality and tone, including "Be genuinely helpful, not performatively helpful." One Redditor argued that Muse is a wrapper app built on OpenClaw and likely carries the same security risks. Meta denied the claims. Nat Friedman, head of product for Meta's Superintelligence Labs, wrote on X that Meta built Muse "from scratch," but acknowledged it was "heavily inspired as a product" by OpenClaw. After first using OpenClaw in January, Friedman said he bought hundreds of Mac Minis for his team at Meta and aimed to build a similar platform "that we could make safe and secure and easy to use and scale to billions of people." He said the team believed OpenClaw creator Peter Steinberger had gotten those things "exactly right."
OpenClaw did not invent AI agents, but it helped move them from proof of concept to useful consumer tools, The Verge reported. It began as a one-man weekend project that ran on users' personal computers and let people communicate with agents through messaging platforms including WhatsApp, Telegram, Slack, Teams and Discord. In about a week, it drew two million visitors and 100,000 GitHub stars, prompting users to buy Mac Minis to run agents continuously, inspiring a social network for AI agents and leading to in-person meetups. OpenAI hired Steinberger in February, Google announced consumer AI agent bets in May, Apple decided to go all-in on agents in June, Instinct grew rapidly in private beta and raised hundreds of millions of dollars in August, and Meta introduced Muse in September, according to The Verge.
Security has been a central issue for both platforms. The Verge reported that one of OpenClaw's top-downloaded skills contained malware and that, by one researcher's analysis, 15 percent of its skill repository contained "malicious instructions" to secretly access user data or perform other suspicious tasks. Zuckerberg wrote that Muse is "built from the ground up for privacy and security" and that user data and credentials are stored on the Muse Secure VM, described as an isolated Linux computer with a browser, CPU, memory and storage. The Verge reported that Meta can still access user data, and that Meta plans to introduce a way later this year to "cryptographically and verifiably prevent Meta from accessing data in your VM." Muse also defaults to letting Meta train and improve its models with user data, though users can opt out.