Security

Meta's Muse AI Assistant Had Zero-Day Flaw Exposing User Accounts

A security researcher discovered that any local app could hijack the authentication token for Meta's new AI agent, which requires extensive system permissions to function.

Omega Editorial· September 23, 2026· 3 min read

Meta's Muse AI Assistant Had Zero-Day Flaw Exposing User Accounts

Meta's recently launched AI assistant Muse contained a zero-day vulnerability that allowed any locally installed application or terminal command to gain complete control over user accounts, according to macOS security researcher Patrick Wardle. The flaw undermined Apple's operating system protections and contradicted Meta CEO Mark Zuckerberg's claims that Muse was "built from the ground up for privacy and security."

Why it matters

AI assistants require unprecedented access to user data and system resources to function—email, calendars, financial accounts, cameras, and microphones. This vulnerability demonstrates how a single design flaw can expose all of those resources at once, creating a single point of catastrophic failure. For enterprises evaluating AI agents, the incident highlights that security claims from even major vendors require independent verification.

How the vulnerability worked

Muse allows users to book appointments, make purchases, generate documents, and connect with services including WhatsApp, email, and social media. To enable these capabilities, users must grant the macOS application extensive permissions that Apple has spent years restricting by default.

Wardle, founder of the Objective-See Foundation and former NASA and NSA employee, discovered that Muse allowed any locally installed app to modify undocumented settings without requiring macOS permissions. While most settings controlled innocuous features like dark mode, one setting allowed processes to change the endpoint where voice transcription occurs—normally a Meta-operated server.

By redirecting transcription to an attacker-controlled server, malicious actors could intercept the authentication token that provides full access to a user's Muse account. "We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars Technica, which first reported the findings. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself."

Wardle developed proof-of-concept attacks that could write malicious files to disk and capture photos without alerting users. He noted that a simple ClickFix attack—a social engineering technique that tricks users into running terminal commands—could trigger the exploit remotely.

Design decisions under scrutiny

Wardle identified two critical design flaws. First, Meta chose to process dictation in the cloud rather than using macOS's built-in on-device transcription, which would have prevented the attack entirely. Second, Meta allowed any app to control all undocumented settings, including the sensitive transcription endpoint.

"At the very least, they should be thinking about security from the very start, and they are just not," Wardle said.

Meta released a hotfix more than 12 hours after Ars Technica published its report. The company's statement characterized the vulnerability as "not a remote exploit," though it did not address how ClickFix attacks could enable remote exploitation or explain why it chose cloud-based transcription over Apple's on-device alternative.

Amazon blocks Muse

Roughly 12 hours before the vulnerability disclosure, Amazon began blocking Muse from its platform, calling it an "unauthorized AI agent" that violates the company's terms of service. Amazon stated that third-party applications making purchases on behalf of customers should "operate openly and respect service provider decisions about whether or not to participate."

Wardle plans to discuss the vulnerability and other AI assistant security threats at the Objective by the Sea conference in November. Details were first reported by Ars Technica.

#ai security#meta#zero-day vulnerability#ai agents#macos security#muse

This is an original analysis by the Omega editorial team. Source reporting: WIRED.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Terrorist Groups Now Using AI to Plan Attacks, Authorities Warn

Recent arrests reveal ISIS and other organizations are leveraging artificial intelligence for weapons guidance, recruitment, and operational planning.

Via AI Watch · Sep 23, 2026
Security· 4 min read

Data Poisoning Threatens AI Models With Just Hundreds of Documents

Research shows attackers can implant backdoors in large language models using surprisingly small amounts of corrupted training data, raising urgent security questions for critical infrastructure.

Via AI Watch · Sep 23, 2026
Security· 2 min read

Rockwell Automation Joins Anthropic's Project Glasswing

The industrial automation giant gains access to Claude Mythos 5 for vulnerability management across manufacturing systems.

Via Automation Watch · Sep 23, 2026