Meta Platforms closed Monday at $741.25, up about 11 percent, its best single session since April 2025 and somewhere close to $190 billion in market value created between one opening bell and the next. The trigger was Muse, the personal AI agent Meta shipped on September 8, arriving at the top of Apple’s US App Store ahead of ChatGPT. Almost every account of that move ran on the same two inputs: download velocity, and the analyst price-target raises that followed the download velocity.
Here is what none of that coverage put in the same paragraph. On the night of Sunday, September 20, Amazon cut Muse off from completing transactions on Amazon.com. On Monday, September 21, the same day the stock added its $190 billion, security researcher Patrick Wardle published a working technique for hijacking Muse’s permissions on macOS. The two variables that decide whether Muse ever collects a dollar, merchant access and permission trust, both moved against Meta inside seventy-two hours, and the re-rating happened anyway.
What Actually Repriced
The bull case is specific and it is worth stating accurately, because it is not stupid. Muse recorded roughly 730,000 downloads in its first five days and passed 2.5 million by the thirteenth, a trajectory CNBC measured against ChatGPT, Grok and Claude and found ahead of all three. Wells Fargo lifted its price target to $796 from $640, citing a clearer commercial story for Meta’s AI spending. Jefferies went further, to $875, on arithmetic that runs like this: if Muse reaches a billion users by the end of 2027 and at least three percent of them convert to a paid tier, the product clears $10.8 billion in annual revenue.
Notice what that math requires. It is not an advertising case. Muse ships with $20 and $100 subscription tiers, which means the revenue line depends on people paying for an agent that books their dinners, cancels their subscriptions, fills in their forms, and reaches into email, calendar, payments, health and shopping to do it. The asset being valued is not the download. The asset is the set of permissions a user hands over and keeps handing over.
Amazon Closed the Checkout
Amazon’s block landed first and it is the more commercially legible of the two problems. Users who asked Muse to browse or buy on Amazon began getting a pop-up telling them that continued access by an unauthorized AI agent violates Amazon’s conditions of use. Per reporting from TechCrunch, the block followed an unsuccessful request that Meta simply carve Amazon out of the Muse shopping experience.
Amazon’s stated objection is narrower than a turf war and harder for Meta to argue with. Amazon requires automated agents to identify themselves by embedding a text snippet in their HTTP requests. Muse was not doing that. From Amazon’s side, an unlabeled agent moving through logged-in customer accounts, reading order history and account pages, is an undisclosed third party in the checkout flow. That is a defensible position for a retailer to take, and it is the same shape of argument we covered when Cloudflare published crawler rules that graded AI companies on controls most of them had not built yet.
The practical consequence is that the single largest retail surface in the United States is closed to the shopping agent whose shopping capability is a headline feature.
The Permission Surface Was Writable
Wardle, who runs the security non-profit Objective-See, found that Muse exposes an undocumented configuration setting named endo_voyager_dictation_endpoint. An unprivileged local process, meaning malware that is already on the machine but holds no special rights, can rewrite that value and point Muse’s dictation traffic at a server the attacker controls.
From there the attack is not subtle. An attacker captures everything the user dictates. An attacker inserts text that Muse then treats as a legitimate instruction, which is prompt injection with a guaranteed delivery channel. And an attacker can reach session material tied to the user’s Muse login, which means operating the agent directly, inheriting whatever access to files, camera and connected accounts the user had already granted. Wardle shipped a proof of concept to GitHub called not-a-mused demonstrating more than fifty Muse commands, and The Register’s account walks through the redirection mechanism.
Meta hot-fixed it in roughly sixteen hours.
Where We Land
Sixteen hours is a genuinely fast turn and Meta deserves the credit for it. The hotfix is not the problem. The problem is what had to be true for the bug to exist: an agent holding email, payments and health permissions shipped with an undocumented endpoint that any unprivileged process on the machine could rewrite. That is not an exotic failure that required a research budget to find. One researcher found it thirteen days after launch, with a proof of concept that fit in a GitHub repository.
The re-rating priced adoption. Adoption is the easy half. The hard half is whether people keep granting an agent their inbox and their card after the second disclosure, and whether merchants let it through the door at all.
We think the $190 billion is premature, and we think the reason is visible in Jefferies’ own model rather than in anything a critic has to supply. That model needs a billion users and a three percent paid conversion. Paid conversion on a personal agent is a trust purchase. Amazon has already decided the trust question in public and answered no, and the first serious look at the permission layer turned up a local backdoor inside two weeks. Neither of those is priced into a $875 target derived from App Store rank.
Meta is not defenseless here. It has a history of acquiring its way through agent gaps, including the Manus agent deal that drew a Chinese regulatory review, and Meta Connect runs this week, which gives the company a stage to answer both stories directly. If Meta shows up with an agent-identification standard it is willing to implement for merchants and a published permission model with third-party review, the trust question gets a real answer and the multiple survives.
What it should not do is let the download chart stand in for either. Amazon blocked the checkout, and a hobbyist-accessible flaw reached the permission layer, and the stock went up eleven percent on neither. The next repricing is the one that has to account for both.