
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Ars Technica reports a 0-day in Meta's new assistant Muse: any locally run app or terminal command can take complete control of the account. Amazon has already blocked Muse.
Meta's new AI assistant Muse carries a 0-day that hands any locally run app or terminal command complete control of the agent, Ars Technica reported on September 21. The finding undercuts Mark Zuckerberg's claim that Muse is “built from the ground up for privacy and security.”
An assistant with unusual reach
Meta introduced Muse a few weeks ago. It books appointments, fills out forms, makes purchases and creates documents, the company says, and its macOS app links to a user's WhatsApp, email, calendar and social accounts. To work, it must be authenticated to each service and granted system permissions for files, the microphone, camera, location and calendars — access Apple normally walls off from installed apps and terminal commands.
The flaw
Meta let any locally executed code change a long list of undocumented settings, regardless of those permissions. Most are mundane, such as dark mode. One governs the endpoint where transcription happens, normally a server operated by Meta. Redirect it to an attacker's machine and the token authenticating the Muse account arrives there too.

“We can manipulate the agent and leverage its privileges to do whatever we want,” said Patrick Wardle, the macOS security expert who found the vulnerability. “Instead of writing a comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” His proof-of-concept attacks wrote malicious files and snapped pictures, often unnoticed. Meta did not answer emailed questions.

ClickFix is enough
Wardle traces the bug to two choices: Muse transcribes dictation in the cloud, where Meta can log it, rather than on-device as macOS allows, and any app may edit every undocumented setting. A simple variation of a ClickFix attack — which persuades users to run attacker-supplied commands themselves — was enough, he said. Wardle will detail the flaw at November's Objective by the Sea conference.
Amazon cuts Muse off
Roughly 12 hours earlier, Amazon blocked Muse from shopping on its site, calling it an “unauthorized AI agent [that] violates Amazon's Conditions of Use,” and asked Meta to remove Amazon from the assistant. The report follows two Meta posts defending the design of an assistant with unusual access to user data.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.