Live
Muse Hit #1. Then Amazon Slammed the Door and a Zero-Day Walked In.
Consumer Apps

Muse Hit #1. Then Amazon Slammed the Door and a Zero-Day Walked In.

Meta launched Muse — an AI agent that shops, books and acts on your behalf — on September 15. One week later it was the number-one free app in Apple’s U.S. App Store, having passed ChatGPT on the way up. That is a genuinely fast start, and it is the last uncomplicated sentence in this story.

Within days, Amazon shut Muse out. Users who pointed the agent at Amazon’s store hit a wall reading, “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use.” Amazon’s stated reasons were specific and, on their surface, reasonable: Meta never told Amazon that Muse would be shopping its store; the agent doesn’t identify itself as an agent while browsing; and it “appears to capture and store customer credentials,” which Amazon framed as a privacy and security risk. “Third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions” about participation, the company said. Meta’s rebuttal: Muse “has no visibility into people’s passwords or payment methods,” with credentials stored so the agent can’t see them.

Take both parties at their word and the fight still isn’t really about your credentials. It’s about the checkout. Amazon has spent two decades building a purchase funnel it owns end to end — the reviews, the Buy Box, the one-click, the ad placements that decide what you see first. An autonomous agent that shops across stores on your behalf is a solvent poured directly on that funnel. It doesn’t see Amazon’s ads. It doesn’t care about the Buy Box. It just buys the thing. Amazon’s security language is sincere and also beside the point: the company is defending its store, not your data. When Amazon says an agent should “respect service provider decisions,” the decision it most wants respected is its own right to be the one that mediates the sale.

Meta’s own demo of Muse shopping on a user’s behalf. Video: Meta.

If the platform fight were the whole story, Muse would still be a case study in how the agent era reorganizes power between the companies that own demand and the companies that own the storefronts. But the same week handed us the other half — the part where the agent is a security surface, not just a business threat.

On September 21, macOS security researcher Patrick Wardle disclosed a zero-day in Muse’s Mac client. An undocumented setting — he named it endo_voyager_dictation_endpoint — could be flipped by a local attacker without elevated privileges, redirecting the agent’s dictation traffic to a server the attacker controlled. From there the attack ladder is ugly: capture the user’s spoken prompts, inject malicious instructions that Muse would then dutifully execute, steal the authentication tokens that let you drive Muse directly, and reach whatever the user had granted the agent — messages, email, finances, even connected iOS devices, tasked invisibly. “Muse’s access can potentially become the attacker’s access,” Wardle wrote. Meta hot-fixed it by September 22, the day after disclosure; Wardle confirmed the patch (“Hooray, hot-fixed!”). Credit where due on the turnaround — but the flaw was a debug setting a non-privileged process could reach, which is less a sophisticated exploit than an unlocked side door.

Muse’s first week, from launch to lockout to patch.
Muse’s first week, from launch to lockout to patch. Graphic: prompt/power.

Put the two halves together and Muse is the agent era in miniature. The product is a hit because delegating the tedious parts of the internet is genuinely appealing. The moment it succeeds, it collides with the platforms whose business model assumes they mediate your transactions — and it becomes a single, permission-rich process that, if hijacked, hands an attacker everything you delegated to it at once. The convenience and the concentration of risk are the same feature seen from two sides. Amazon slammed the door to protect its funnel. Wardle showed why you might want the door to have a better lock. Neither was really arguing about you — and that, more than the download chart, is the thing worth watching.

Sources

// Columnist, Consumer Tech
Lauren Smith

Lauren Smith covers consumer apps and services for prompt/power: streaming, subscriptions, e-commerce and everyday tech worth your money. She keeps a running tally of every free trial that quietly turned into a subscription.

Latest from prompt/power

  1. Gemini’s Free Tier Shrinks Oct. 9: What You Keep and What Costs ExtraOct 5
  2. How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
  3. OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
  4. When an AI Agent Breaks In, Who Answers for It?Oct 5
  5. The New AI Models Don’t Talk. They Decide.Oct 5

Leave a Reply

Your email address will not be published. Required fields are marked *