Last updated: September 21, 2026
Meta’s Muse AI App Tops App Store Charts Amid Security Flaws and Retailer Pushback
Meta Platforms has surged past major milestones with the recent launch of its personal AI assistant, Muse, climbing to the top of free app charts on the U.S. App Store. Designed to handle multi-step workflows like booking travel and filling out electronic forms, the app recorded millions of downloads in its first two weeks. However, the rapid rollout has triggered immediate industry friction, drawing a swift block from e-commerce giant Amazon and exposing a critical zero-day security flaw that researchers say could allow malicious local apps to hijack user accounts.
The Story at a Glance
Launched on September 8, Muse is an AI assistant powered by Meta’s Muse Spark family of models. The application is available for free with optional monthly subscriptions priced at $20 and $100 for heavy users. Data from analytics firms shows that Muse clocked roughly 2.5 million to 2.8 million downloads within its first 12 days, outpacing the early debut figures recorded by OpenAI’s ChatGPT during a similar post-launch window. The momentum helped push Meta shares up more than 11% in recent trading, adding significant market capitalization as Wall Street analysts turned increasingly bullish on the company's new AI monetization strategy.
How the Story Developed
Interest in agentic AI tools escalated earlier in the year, prompting major technology firms to accelerate consumer-facing personal assistant releases. Following its debut on iOS and Android platforms, Muse quickly gained traction as early users shared viral examples of the assistant securing lower insurance rates and executing online retail purchases. But the rapid adoption drew scrutiny regarding system permissions and data privacy. On Sunday, Amazon blocked the assistant from accessing its shopping platform, stating that the app bypasses built-in personalization features and captures customer credentials without advance permission. Shortly afterward, security researcher Patrick Wardle disclosed a zero-day vulnerability in the macOS version of Muse, revealing that local applications could manipulate undocumented settings to redirect voice transcription data to an attacker-controlled endpoint. Meta issued a hotfix patching the vulnerability within 12 hours of the public disclosure.

Key People and Details
The rollout highlights key contributions from industry leaders and security experts navigating the emerging agentic software ecosystem. Meta Superintelligence Labs executive David Singleton addressed the security disclosures by noting that the exploit required local code execution, describing the practical risk to users as relatively low. Meanwhile, independent security researcher Patrick Wardle demonstrated how easily a standard social engineering tactic could be leveraged against unprivileged settings in the macOS application. On the commercial side, Shopify CEO Tobias Lütke confirmed a partnership with Meta to support agentic checkout features, contrasting with Amazon's decision to restrict unauthorized bots from its storefront.
This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low.
Reaction and Response
Industry analysts have offered mixed assessments of Meta's latest consumer software push. Financial institutions raised their stock price targets following the strong download metrics, with J.P.Morgan analysts suggesting that the app possesses strong product-market fit. Conversely, security specialists raised broader questions regarding the deep operating system permissions required by personal assistants that interface with private messaging, calendars, and file storage. Retailers have similarly pushed back against third-party tools operating outside official terms of service agreements.
What to Watch
Observers are closely monitoring whether Meta can sustain user engagement after the initial launch excitement fades, given that other high-profile AI tools have experienced rapid early adoption followed by steep drop-offs. Key issues to watch include whether additional major e-commerce platforms will follow Amazon's lead in restricting automated agents, how effectively upcoming software patches protect local device resources, and whether regulatory bodies will scrutinize the data privacy practices of hyper-privileged assistant platforms.
Frequently Asked Questions
What is Meta's Muse app?
Muse is an AI personal assistant developed by Meta that can execute multi-step tasks such as managing emails, filling out forms, organizing calendars, and making purchases on behalf of users.
Why did Amazon block the Muse assistant?
Amazon blocked Muse because it operates as an unauthorized AI agent that bypasses site personalization features, captures user credentials, and violates the platform's conditions of use without prior authorization.
How serious was the zero-day security flaw found in Muse?
Security researcher Patrick Wardle discovered a zero-day vulnerability in the macOS app that allowed local applications to redirect voice transcription data to external endpoints and hijack user accounts. Meta released a hotfix to patch the issue.
How does Muse pricing work?
The basic version of the Muse application is available for free, while Meta offers monthly subscription tiers priced at $20 and $100 for users requiring heavier operational capacity.
Resources
Sources and references cited in this article.
