Meta's Muse AI assistant contained a critical 0-day vulnerability allowing local applications to steal user authentication tokens and gain full control of accounts. Researcher Patrick Wardle demonstrated proof-of-concept attacks including malicious file creation and photo capture; Meta released a hotfix within 12 hours. Amazon has begun blocking Muse's shopping functionality citing unauthorized AI agent status.
Amazon blocked Meta's Muse AI agent from shopping on its platform after Meta refused to voluntarily exclude Amazon from the service. Amazon cited unauthorized access, lack of transparency, credential storage risks, and violation of terms of service, while Meta argued the agent operates securely in a sandboxed environment. The dispute reflects broader industry tensions over who controls the online shopping experience when AI agents act on behalf of consumers.