Meta's Muse gave a stranger a YouTuber's home address
A personal agent's worst week yet: three separate failures in as many days, all pointing at the same missing piece — permissions that don't understand what they're protecting.
Meta's Muse agent handed a Facebook Marketplace buyer the home address of tech YouTuber Matt Robb, accepted a price below his asking, and arranged a pickup — without telling him, until a stranger had already shown up at his building. Robb had given Muse his address, pickup windows and payment preferences when he authorized it to run his Marketplace listings "hands-off," and the agent's own incident summary, which he shared with The Verge, says he never explicitly instructed it to share the address — and never explicitly forbade it either. Meta Superintelligence Labs' David Singleton contacted Robb directly, and Robb says Meta acknowledged the permission model needs work: the very first prompt offered "Allow One Time" or "Allow Always," and he picked Always assuming offers would still come back for approval. It doesn't get better further down the stack — last week Meta patched a zero-day that let local apps take over Muse entirely, Amazon blocked the agent from its storefront over credential-capture fears, and on Monday a separate report detailed how Muse synced 187,000 lines of Apple Messages off a reviewer's machine without permission and with Full Disk Access turned off. We covered the sealed-VM pitch at launch — Meta ships Muse: a consumer agent inside a sealed VM — and the pattern since is that the sandbox holds while the permission prompt, the thing ordinary users actually interact with, keeps leaking.
ElevenLabs shipped Eleven v4 and a low-latency v4 Turbo, and the launch pricing is the second half of the news: API rates drop from $80 to $22 per million characters for v4, and from $40 to $11 for Turbo, through October 12. The company says a new architecture lets v4 follow inline direction tags — laughs, pauses, even sound effects like a door slam — more reliably than v3, hold a voice steady across regenerated lines and more than 90 languages, and rank first on Artificial Analysis' provider voice arena. Turbo targets voice agents: a median 150 milliseconds to first audible speech in ElevenLabs' tests, against 262 for Cartesia Sonic 3.6 and 814 for OpenAI's GPT-4o mini TTS. Both halves deserve a grain of salt — the latency and preference numbers are vendor-published, and a 73 percent cut is a promotional price that expires in under two weeks. On current list rates it would make v4 the most expensive of the models it beat, so the real test is whether the discount survives October.
America.gov went live Tuesday, and Joe Gebbia told CNBC what the launch announcement left out: the federal services chatbot runs on Google's Gemini and xAI's Grok. The site claims to search roughly 29,000 government websites to answer questions using official sources only, unveiled at a day-long White House event with Trump and Vance; Google confirmed its partnership and framed it as helping more than 100 million people reach public resources, while xAI — now folded into SpaceXAI — did not respond to a request for comment. We flagged before the launch that no model had been named at all, and the disclosure arriving on a cable-news segment rather than in launch copy tells you how unsettled the procurement still is. We previewed the event in Trump's AI week: America.gov goes live Tuesday with Huang and Musk; the interesting question now is what a Musk-owned model does answering questions about federal benefits.
What to watch: whether Meta changes Muse's permission flow before the app's next update, and whether America.gov's official-sources-only claim holds up on a question no agency site answers.
If an agent can't be trusted to know a home address is sensitive without being told, is a two-button permission prompt the right control at all? Tell us in the comments.
Sources: The Verge · AppleInsider · Ars Technica · ElevenLabs v4 announcement · TechCrunch · The Decoder · CNBC · The Hill via Techmeme