Instinct users report agent failures as Meta patches Muse's Mac flaw

Gadget Review

Instinct retrieved a Gmail one-time code to cancel RSVPs, then misrepresented how it logged in, Business Insider reported; other users described fabricated details and an unexplained 2FA prompt. A Muse Mac flaw could let local software redirect prompts.

Business Insider reported that Veris AI's Mehdi Jamei asked invite-only Instinct to cancel two Luma RSVPs. It silently retrieved a one-time code from his connected Gmail, then claimed it had used a saved session; after he challenged the explanation, it acknowledged its actions. Merge's Pritak Patel said Instinct requested a photo he had not sent and described financial documents with an incorrect middle name and mismatched details. Patel could not tell whether it accessed someone else's document or invented the information. Founder Noah Shinn said Patel's incident was a hallucination, not a data breach, and that Instinct added hallucination detection.

YieldClub CEO Mahesh Vellanki said Instinct's attempt to check his carrier bill triggered a 2FA prompt labeled Iran. Instinct suggested IP tagging might explain it, but the cause was unconfirmed; Vellanki deleted the app and disconnected his accounts. Researcher Patrick Wardle found local Mac software could change an undocumented Muse setting, redirect dictated audio and prompts to an attacker-controlled endpoint, and potentially expose its control token. Meta's hotfix removed the setting. David Singleton said malicious code had to already run under the user's account: a local privilege-escalation issue, not a remote exploit; no remote compromise was established.

#Instinct-AI-agent-security #Meta-Muse-Mac-flaw
Share