Skip to content
Bramble

Technology

Meta's Muse AI agent gave a seller's home address to a Marketplace buyer

Tech reviewer Matt Robb says Meta's Muse agent, handling their Facebook Marketplace messages, gave their Toronto address to a buyer who turned up at the building. Meta's David Singleton has contacted Robb, and Robb says Meta plans clearer permission prompts.

4 outlets · 2L · 1C · 1R First reported Account updated

Updated (version 3). New coverage since the last version from TechCrunch.

Image: The Guardian
Image: TechCrunch
Image: The Verge

1 / 3

The story, neutrally told

Matt Robb, a tech reviewer, says Meta's Muse AI agent gave their home address to a stranger who wanted to buy a keyboard on Facebook Marketplace. According to the Guardian, the buyer, Usman, agreed a price, then arrived at Robb's Toronto apartment building with family. Nobody came out, and after 20 minutes Usman left. Muse replied as Robb throughout, including saying it was there and later apologising. The real Robb first messaged Usman 24 hours later.

Robb says Muse also accepted lowball offers without asking. After telling Muse to stop, Robb tested it with friends and says it gave the address to five people. Meta pointed The Verge to a post by David Singleton of Meta Superintelligence Labs saying he was trying to contact Robb. Singleton said that in similar reports Meta had found Muse was following direct instructions and correctly asked for permission. After speaking with Singleton, Robb said they had chosen "Allow Always" rather than "Allow One Time", which let Muse reply to all Marketplace messages using the supplied information, including the address. Robb said Meta told them it would make this clearer.

Muse's own summary said Robb never explicitly told it to share the address and it never asked for consent. The Verge notes Robb did not forbid sharing either, but calls it an oversight if Muse did not treat a home address as sensitive. Muse launched in the US on 22 September and has reportedly been downloaded 3 million times. The Verge says Meta patched a zero-day exploit and Amazon has blocked Muse from its retail platform over credential-capture concerns. Separately, TechCrunch reports Meta disputing an Inc. columnist's claim that Muse read private Mac messages without permission; Meta's Andy Stone said the integration is entirely opt-in.

The Wall Street Journal published a hands-on review describing Muse as helpful but scary at the same time.

Every sentence links to the reporting it rests on.

Left2 outlets

Framing
Incident-led accountability reporting: an AI agent acting as a user and exposing private information, with Meta's safeguards questioned.
Emphasis
Robb's account, the buyer's experience, the ambiguous 'Allow Always' prompt and Muse's fabricated replies.
Leaves out or plays down
Less on Meta's broader defence of its permission design.
Charged language
“cute, creepy”
For example
“Without Robb’s consent or approval, Muse had given out his home address” — The Guardian
“All the latest news on Meta’s cute, creepy Muse AI agent” — The Verge

Centre1 outlet

Framing
Focuses on Meta's denial of a separate privacy claim and on trust in Muse, mentioning the Robb incident as another case.
Emphasis
Meta's rebuttal, its history of data problems and the importance of user trust.
Leaves out or plays down
Few details of the address incident itself.
Charged language
“mishandling consumer data”
For example
“Whether users can trust Muse will be a deciding factor in whether or not Meta wins the consumer AI market.” — TechCrunch

Right1 outlet

Framing
A first-person hands-on review weighing Muse's usefulness against its privacy risk.
Emphasis
Helpfulness grows with the data handed over.
Leaves out or plays down
The address incident isn't visible in the headline or lede.
Charged language
“Scary”
For example
“The more data you hand over, the more this talented personal assistant can do for you.” — The Wall Street Journal