Analysis
A week after The Information disclosed a security vulnerability in Meta's Muse AI agent, the follow-on story isn't about the bug -- it's about whether anyone should trust Meta with the app at all. TechCrunch's hands-on review this week, after weeks of daily use, credits Muse with at least one genuine win -- surfacing unclaimed funds the reviewer didn't know existed -- but comes back to the same unresolved question: can users trust Meta's ad-funded business with the sensitive financial and personal tasks an agent like Muse is designed to handle.
What Changed Since The Vulnerability
Meta's answer since the disclosure has been architectural rather than just a patch. The company says Muse runs inside a dedicated "Muse Secure VM," its own sandboxed environment with a separate browser, and that it doesn't share people's Muse conversations or data with Meta's advertising systems. That's a step beyond the in-app warning Meta strengthened right after the vulnerability surfaced -- an attempt to answer the trust question structurally instead of just disclosing risk.
“## What Changed Since The Vulnerability Meta's answer since the disclosure has been architectural rather than just a patch.”
The Gap Between The Fix And The Feeling
Critics aren't convinced the fix closes the gap. Meta's core business is selling ads against user data, and the company's history -- from Cambridge Analytica to this month's own $200 billion New Mexico privacy verdict -- makes "trust us, it's sandboxed" a hard sell regardless of the technical architecture underneath it. The downside for Meta is that skepticism compounds with every headline like this one, regardless of what's actually true about the VM's isolation. Muse launched at Meta Connect earlier this month as Zuckerberg's bet that a consumer AI agent, not another coding tool, is Meta's wedge into the agent economy; the trust question is now the thing standing between that bet and mainstream daily use.
Nothing here suggests Muse's growth has slowed -- Meta has kept expanding its feature set and access even through the vulnerability disclosure. The real test isn't whether Muse gets more capable, but whether Meta ever produces a trust signal stronger than a separate VM.