Meta's Muse AI assistant exceeds early ChatGPT downloads despite emerging security and access challenges.

Muse uses a human-in-the-loop system for sensitive actions such as purchases and account changes, requiring user approval before proceeding. Meta also says the assistant runs in secure virtual machines to compartmentalize data during task execution.
Meta offers Muse in three tiers: a free plan with usage limits, a $20-per-month “Power” plan and a $100-per-month “Maximum” plan for heavier users.
Apptopia estimates that more than 95% of Muse’s early users were also Facebook users and 63% used Instagram, indicating substantial overlap with Meta’s existing social-media audience.
The zero-day vulnerability reportedly exposes the token used to authenticate a user’s Muse account and lets local applications or terminal commands alter undocumented settings, including the endpoint used for transcription—despite macOS permission restrictions.
Muse’s capabilities extend beyond text chat to multimodal text, image and video generation, a feature set that Meta is positioning for creative and business workflows such as media and marketing production.
Meta's new Muse AI assistant hit the top of Apple's U.S. App Store within 10 days of launch, drawing 1.8 million iOS downloads in the U.S. and Canada and surpassing ChatGPT's early performance. Yahoo Finance reported the app reached roughly 642,000 daily active users and sparked an 11% jump in Meta's stock, signaling Wall Street's enthusiasm for consumer AI agents that can book appointments, manage calendars, and make purchases across apps like Gmail, Spotify, and Instagram.
Yet Muse's rapid rise faces early friction. GeekWire revealed that Amazon blocked the assistant from its site on September 20, and security researchers disclosed a serious macOS vulnerability that could expose authentication tokens and let local applications hijack the agent—casting doubt on Meta's privacy and security claims just weeks after launch.
Muse secured 730,000 downloads within its first five days, according to Yahoo Finance, far outpacing ChatGPT's early iOS numbers. Third-party estimates show 2.8 million global installations in 12 days. Data from Apptopia reveals that 95% of early users already had Facebook accounts and 63% used Instagram—indicating Meta successfully channeled its existing social-media audience into the new AI product.
Meta is monetizing Muse through a three-tier model: a free plan with usage limits, a $20-per-month Power plan, and a $100-per-month Maximum plan. The strong early adoption and stock surge—Crypto Briefing reported Meta's largest single-day gain since April—has renewed investor appetite for AI-native consumer platforms and lifted semiconductor stocks on expectations of increased computing demand.
On September 20, Amazon barred Muse from accessing its site, displaying pop-up warnings to users attempting to shop via the agent. An Amazon spokesperson said third-party applications making purchases on behalf of customers "should operate openly and respect service provider decisions about whether or not to participate." GeekWire reported the block, noting it echoes Amazon's earlier resistance to Perplexity's Comet browser and ChatGPT agents.
The friction signals a broader "agentic turf war," as analysts warn. If AI agents become the primary gatekeepers for consumer queries, retailers risk losing direct relationships with customers. Amazon's move suggests e-commerce platforms will fight aggressively to preserve their control over product discovery, pricing, and personalized recommendations—even as AI agents reshape how people shop online.
Days after GeekWire reported Amazon's block, security researchers disclosed a zero-day vulnerability in Muse's macOS application. The flaw reportedly allows local applications or terminal commands to bypass macOS permission restrictions, extract the authentication token used to access a user's Muse account, and alter undocumented settings—including the endpoint for voice transcription.
Meta has emphasized that Muse uses a human-in-the-loop system requiring user approval before sensitive actions like purchases or account changes. The company also claims the assistant runs in isolated virtual machines to compartmentalize data and generates single-use payment tokens through Stripe Link. Yet the macOS vulnerability undercuts those assurances, raising questions about whether Muse's security architecture can withstand real-world threats.
Muse extends beyond text chat to generate images and video, a feature set Meta is promoting for creative and business workflows. The assistant can draft marketing copy, edit media, and coordinate across Facebook, Instagram, and WhatsApp—tools designed to appeal to content creators and small businesses. This multimodal approach differentiates Muse from text-only chatbots like ChatGPT, positioning the agent as a full-featured productivity suite.
Publishers
41
Articles
22
Reach
63