
Meta classified a newly disclosed Muse vulnerability as SEV-2 (its third-highest severity), after an external researcher reported it via the company's bug bounty program. The flaw could have allowed unauthorized access to a user's Muse Secure VM — the dedicated cloud computer storing emails and files. Meta says it is updating the safety warnings inside the agent. This is a distinct disclosure from the Sept 28 Patrick Wardle zero-day, which Meta hotfixed more than 12 hours after disclosure.