Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day

by | Sep 27, 2026 | Technology

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Meta’s newly introduced AI assistant Muse, unveiled a few weeks prior, has been found to contain a significant zero-day vulnerability that allows locally installed applications and terminal commands to gain unauthorized control over the agent. The vulnerability was discovered by macOS security researcher Patrick Wardle and enables attackers to completely hijack user accounts and manipulate the assistant’s capabilities.

Muse is designed to handle a wide range of tasks including appointment booking, form completion, customer service interactions, and purchases. The application operates on macOS and integrates with user accounts across WhatsApp, email, calendar, and social media platforms. To function, users must grant Muse extensive permissions to access operating system resources including file writing, microphone and camera access, location monitoring, and calendar data. The zero-day exploit takes advantage of poorly secured design decisions by exposing an authentication token that provides complete account access.

According to Wardle, the vulnerability stems from multiple design flaws in Muse’s architecture. The assistant performs voice transcription on Meta’s cloud servers rather than locally on the device, and it allows any application to modify undocumented settings, including the endpoint address where transcription data is sent. Attackers can redirect this endpoint to their own servers, intercepting authentication tokens and gaining permanent control over compromised accounts. Wardle demonstrated proof-of-concept attacks capable of writing malicious files and capturing images with no user notification.

Meta released a hotfix patching the vulnerability more than 12 hours after the disclosure became public. The discovery raises concerns about the security development process for an agent with such extensive system access. Additionally, Amazon began blocking Muse from its platform on Sunday, stating that unauthorized third-party agents violate its terms of service and demanding Meta remove the retailer from Muse’s available services. Meta subsequently stated that third-party agents should operate transparently and respect service providers’ participation decisions.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI