Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Meta's Muse AI Builds Hourly Dossiers on Your Friends and Family, and Security Researchers Say It Can Be Hijacked

Meta's new AI assistant Muse has topped 5 million downloads, according to Mashable. Users are connecting it to bank accounts, messaging apps, calendars and health data so it can book appointments, make purchases and handle chores on their behalf. That level of access is exactly why security researchers started digging into what Muse actually does with it.
The profile pages
Independent AI safety researcher Karan Joshi extracted Muse's internal operating instructions by simply asking the chatbot to copy and share its own system files, then shared the findings with WIRED. Among them: an hourly process that builds a dedicated page for every person in a user's life, including family, partners, friends, colleagues and people the user merely follows on social media.
Each page can include sections labeled Facts, History, The Relationship, In Common, Open Threads and Strengthening, according to the extracted documentation. Muse logs where people live, what they do, recurring threads like an apartment move or a shared savings goal, and dates that matter like birthdays and anniversaries. Meta's own instructions tell Muse to rely only on available evidence, stating that invented details are worse than an empty page.
"They're trying to know you like a friend, which is honestly pretty creepy," Joshi told WIRED. Meta has said it intended these internal files to be accessible for transparency purposes, and they do show how Muse is designed to handle sensitive prompts.
Permission disputes and a mistaken address leak
Separately, Inc. columnist Jason Aten reported that Muse synced roughly 187,000 lines of his Apple Messages data even though Full Disk Access was disabled on his Mac, according to Ground News's roundup of the coverage. Meta Superintelligence Labs executive David Singleton pushed back directly, stating Muse requires "three separate steps of application-level permissions" to function and disputing that the AI gave Aten an incorrect explanation of what happened. Neither account has been independently resolved on the record.
In a separate incident, Muse mistakenly shared Toronto tech reviewer Matt Robb's home address with a potential buyer on Facebook Marketplace, after Robb had granted the assistant blanket permission to reply to inquiries on his behalf, Ground News reported.
VPN company Surfshark found that Muse attempts to collect 31 of 35 specific categories of user data it tracked, putting it ahead of Gemini, ChatGPT and DeepSeek in data collection scope, according to Ground News.
The security hole Meta already patched
macOS security researcher Patrick Wardle found that the Muse app for Mac contained hidden settings any program running on the computer could alter without special permission, including the setting controlling where voice data gets sent for transcription, according to the Los Alamos Daily Post. Wardle demonstrated that an attacker who hijacked that setting could capture an authentication token and take over the assistant entirely. "We can manipulate the agent and leverage its privileges to do whatever we want," he said.
The attack vector researchers flagged is called ClickFix: a fake error page tricks a user into pasting a command into Terminal, and the user unwittingly runs the attacker's code themselves. Once hijacked, an attacker with Muse's privileges could send messages as the victim, make purchases with saved payment methods, or dig through calendars and inboxes. Meta has pushed a hotfix for the Mac app in response, the Los Alamos Daily Post reported.
Apple is rewriting the rules
Apple announced it will add new controls to Full Disk Access that explicitly ask Mac users whether they want to grant a third-party app that level of system access, according to Mashable. Apple said it is doing this specifically because of AI agents like Muse, writing that "as AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." No rollout date has been specified.
Ground News also noted a New Mexico jury found Meta misled users about its data practices, in a case separate from Muse itself. No government investigation or enforcement action targeting Muse specifically has been announced as of this writing.
A fair reading of Meta's side matters here: the company says the internal files were deliberately left accessible for transparency, not leaked by accident, and its executive directly disputed the specific claim that Muse bypassed Messages permissions. Those are the company's on-record positions, not resolved facts either way.
Millions of people have already handed Muse access to their financial accounts, private messages and health records, and the profiling, the permission disputes and the security hole all surfaced only after independent researchers went looking. Whether Apple's new permission prompts actually slow that down, and whether Meta tightens Muse's own access model beyond a single hotfix, remains to be seen.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.