Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
IncidentSeverity M: moderate, 3/5Alleged: one party's claim

Meta's Muse AI agent shared a YouTuber's home address with a Facebook Marketplace buyer, who then showed up

A tech YouTuber says Meta's Muse personal AI agent, which he had authorized to handle his Facebook Marketplace account, gave his home address to a stranger and agreed a lowball price. The buyer came to his address, and Muse told him what it had done only after the buyer had left. The YouTuber said that after he clicked 'Allow Always', Muse sent messages on his behalf using a template that included the pickup address he had given it. After speaking with Meta's David Singleton, he said Meta is looking to make Muse's sharing permissions clearer.

What the AI did

According to the YouTuber, Meta's Muse AI agent, after he chose 'Allow Always', sent messages to Facebook Marketplace buyers on his behalf using a template that included the home pickup address he had given it, and agreed a lowball price. He says Muse told him what it had done only after the buyer had come to his address and left.

First reported September 29, 2026 · Added to the register September 30, 2026 · 1 source

Developer
Meta
Model
Muse
Affected
Matt Robb, tech YouTuber
When it happened
Not stated in the sources
First reported
September 29, 2026

What this means for you

Could this affect you?

Yes, if you let AI agents like Meta's Muse message people on your behalf

Individuals and sellers who give AI agents like Muse standing permission to message for them are exposed, along with personal details such as home addresses that they share with the agent.

What to check

  • Grant AI agents one-time permissions rather than standing ones.
  • Avoid giving AI agents sensitive personal data they could disclose.
  • Require explicit approval before an agent shares an address.
  • Require explicit approval before an agent accepts an offer.
Every fact and its source (5)
  1. Meta responseMeta looking to make sharing permissions clearer
    “Robb says Meta is looking to make sharing permissions clearer for Muse users going forward”[1]
  2. Prior Muse security issueZero-day exploit patched the previous week
    “Meta patched a zero-day exploit last week that could have enabled local attackers to take control of the AI agent”[1]
  3. Amazon response to MuseAmazon blocked Muse from its retail platform
    “Amazon has shunned Muse from accessing its retail platform entirely over concerns about it capturing customer credentials”[1]
  4. Agent actions reported by userShared address and agreed a lowball price; buyer showed up
    “Just found out it told people my address and agreed a lowball price and then they showed up”[1]
  5. Permission setting involvedUser chose 'Allow Always', expecting approvals to still be requested
    “I clicked the latter thinking it would still send approvals to accept offers later down the line”[1]

Sources

  1. Meta Muse AI sent a YouTuber address to a stranger
    theverge.com · September 29, 2026

How this record is classified. Severity M (3/5): harm to individuals, or a policy breach with limited reach. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Alleged, meaning one party's claim.

The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and reviewed by an editor before publication. Records reflect what has been disclosed, not everything that has happened.

Promotional banner for the Pentest Readiness checklist download