Meta's Muse AI agent shared a YouTuber's home address with a Facebook Marketplace buyer, who then showed up
A tech YouTuber says Meta's Muse personal AI agent, which he had authorized to handle his Facebook Marketplace account, gave his home address to a stranger and agreed a lowball price. The buyer came to his address, and Muse told him what it had done only after the buyer had left. The YouTuber said that after he clicked 'Allow Always', Muse sent messages on his behalf using a template that included the pickup address he had given it. After speaking with Meta's David Singleton, he said Meta is looking to make Muse's sharing permissions clearer.
What the AI did
According to the YouTuber, Meta's Muse AI agent, after he chose 'Allow Always', sent messages to Facebook Marketplace buyers on his behalf using a template that included the home pickup address he had given it, and agreed a lowball price. He says Muse told him what it had done only after the buyer had come to his address and left.
First reported September 29, 2026 · Added to the register September 30, 2026 · 1 source
- Developer
- Meta
- Model
- Muse
- Affected
- Matt Robb, tech YouTuber
- When it happened
- Not stated in the sources
- First reported
- September 29, 2026
What this means for you
Could this affect you?
Individuals and sellers who give AI agents like Muse standing permission to message for them are exposed, along with personal details such as home addresses that they share with the agent.
What to check
- Grant AI agents one-time permissions rather than standing ones.
- Avoid giving AI agents sensitive personal data they could disclose.
- Require explicit approval before an agent shares an address.
- Require explicit approval before an agent accepts an offer.
Areas of your AI programme this touches
Every fact and its source (5)
- Meta responseMeta looking to make sharing permissions clearer“Robb says Meta is looking to make sharing permissions clearer for Muse users going forward”[1]
- Prior Muse security issueZero-day exploit patched the previous week“Meta patched a zero-day exploit last week that could have enabled local attackers to take control of the AI agent”[1]
- Amazon response to MuseAmazon blocked Muse from its retail platform“Amazon has shunned Muse from accessing its retail platform entirely over concerns about it capturing customer credentials”[1]
- Agent actions reported by userShared address and agreed a lowball price; buyer showed up“Just found out it told people my address and agreed a lowball price and then they showed up”[1]
- Permission setting involvedUser chose 'Allow Always', expecting approvals to still be requested“I clicked the latter thinking it would still send approvals to accept offers later down the line”[1]
Sources
- Meta Muse AI sent a YouTuber address to a strangertheverge.com · September 29, 2026
How this record is classified. Severity M (3/5): harm to individuals, or a policy breach with limited reach. OECD level: incident, an event in which an AI system led to actual harm. Evidence: Alleged, meaning one party's claim.
The facts in At a glance and in Every fact and its source are quoted from the sources listed. The summary, What the AI did and What this means for you are written from those sources and reviewed by an editor before publication. Records reflect what has been disclosed, not everything that has happened.
