Meta’s Muse faces zero-day flaw as Amazon blocks shopping access
Meta’s Muse AI assistant faces a zero-day flaw, while Amazon has blocked it from shopping on its marketplace.
Amazon began blocking Muse from its site on Sunday, adding another problem for the assistant. Meta introduced Muse a few weeks ago. According to Ars Technica, the assistant can book appointments, fill out forms, handle customer service, take tasks off a user’s plate, make purchases, generate images, create documents, and connect with apps and services. The macOS app, for which there is no Windows version, also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that does not exist, Muse creates one on the fly.
For Muse to perform those tasks, users must give it access to their accounts, including authenticating the assistant with each service. Because the app runs on macOS, users must also grant it permissions to operating-system-restricted resources such as writing files to disk, accessing the microphone and camera, and monitoring location and calendars. Apple has spent years developing defenses to prevent installed apps or terminal commands from accessing those resources. According to Ars Technica, Muse undoes those default measures.
SiliconANGLE reported that Amazon blocked Meta’s Muse agent from accessing its e-commerce marketplace and notified users late Sunday. Meta made Muse available in the United States earlier this month through a mobile app. The agent topped 730,000 downloads within five days, ahead of ChatGPT and Claude, and by last Friday it had surpassed OpenAI’s chatbot as the most popular free app on the App Store. Meta offers a free version alongside two paid editions with higher rate limits.
Investors did not treat the Amazon block as a major blow to Muse’s momentum. Meta shares closed more than 11% higher today. Intel, Advanced Micro Devices, and Arm Holdings also posted double-digit gains. The three companies are major providers of central processing units, which AI agents use heavily to run their tools. The stock rally suggests Wall Street does not expect Amazon’s ban to dent Muse’s popularity.
Amazon told GeekWire in a statement that third-party applications offering to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether to participate. Amazon said one motivation for the block is that Muse does not identify itself as an agent when making purchases. Its terms of service require agents to identify themselves by embedding a text snippet in HTTP requests. Amazon also took issue with Muse’s ability to access customer data, saying the agent can view a user’s Amazon account pages and purchase history if prompted. GeekWire reported that Amazon believes such activity “amounts to an undisclosed third party moving through customer accounts.”
Meta may seek to address those concerns to lift the ban. The company has said it is actively working to expand Muse’s data protection guardrails. Muse launched with a security mechanism called the Muse Secure VM, which deploys each Muse instance in a virtual machine that isolates it from the rest of Meta’s infrastructure. A second, cybersecurity-optimized agent called Sentinel reviews sensitive actions such as online purchases and prevents Muse from directly accessing credit card numbers and account credentials. Meta can currently theoretically access data in consumers’ Muse instances, according to SiliconANGLE. The company is developing an enhanced version called the Muse Confidential VM that is intended to make such access impossible. It is set to roll out later this year, and Meta is testing it with a limited number of users.
Amazon has blocked other agents before. Last year it sued Perplexity AI over its Comet browser, which includes an AI agent that can shop on users’ behalf. An appeals court dismissed the case in August, but it did not bar Amazon from blocking agents that breach its terms of service.