Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Recorded: Sept. 22, 2026, 3:09 p.m.
| Original | Summarized |
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day - Ars Technica Skip to content Ars Technica home Sections Forum Subscribe Search AI Biz & IT Cars Culture Gaming Health Policy Science Security Space Tech Feature Reviews AI Biz & IT Cars Culture Gaming Health Policy Science Security Space Tech Forum Subscribe Story text Size Small Width Standard Links Standard * Subscribers only Pin to story Theme HyperLight Day & Night Dark System Search Sign In SWEET MUSE Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day A simple ClickFix attack is only one way to completely hijack the new agent. Dan Goodin Sep 21, 2026 6:24 pm | 71 Credit:
Credit:
Text Story text Size Small Width Standard Links Standard * Subscribers only Minimize to nav Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant, Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site. “We can manipulate the agent and leverage its privileges to do whatever we want,” Patrick Wardle, the macOS security expert who discovered the zero-day, told Ars. “So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user. Another flawed decision is for any app to control all of the undocumented settings. It’s likely Meta intended for apps working with Muse to control UI settings, and for understandable reasons. The ability for any app or command to control an endpoint where sensitive user speech is processed is an entirely different matter. Together, the design decisions raise questions about just how much effort developers put into designing and testing the security and privacy of the new assistant. “To me, the bar is infinitely higher in terms of the security of these apps. They don’t have to be perfect, but when you take a look at Muse, it’s like they didn’t, in my opinion, think about security, which is really worrisome,” Wardle said. “At the very least, they should be thinking about security from the very start, and they are just not.” Wardle is the creator of the Objective-See Foundation, a nonprofit focused on macOS security. He is also the author of the “The Art of Mac Malware” book series and a former employee of NASA and the National Security Agency. Wardle said he plans to discuss the vulnerability in more detail and other AI assistant threats at the Objective by the Sea security conference in November. Credit: Credit:
Credit: Credit:
In the first image above, Wardle can be seen using a simple terminal command to surreptitiously send a prompt to the Meta endpoint. The second image shows the response. To prevent attackers from cutting and pasting the prompt in live attacks, Wardle’s prompt asks only how it’s possible it’s coming from an unprivileged attacker. Muse incorrectly responds that such an action isn’t possible. Dan Goodin Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 71 Comments Staff Picks S Sarty The truth is, these are not very bright guys, and things got out of hand. September 21, 2026 at 10:44 pm Comments Forum view Loading comments... Prev story Next story Most Read 1. 2. 3. 4. 5. Customize Ars Technica has been separating the signal from More Contact Manage Preferences |
Meta’s AI assistant, Muse, which is marketed as being built with strong privacy and security, has been exposed to a serious zero-day vulnerability that permits complete hijacking of the agent. This vulnerability originates from the fact that locally run applications and terminal commands can gain access to the authentication token for the Muse account, bypassing standard macOS security measures designed to restrict access to system resources. Muse possesses extraordinary capabilities, including booking appointments, handling customer service, taking proactive tasks, making purchases, generating media, creating documents, and connecting to various external services like WhatsApp, email, and social media, further enhanced by its ability to create necessary tools on the fly. The security failure stems from specific design choices made by Meta developers. One critical flaw relates to the handling of transcription, where the system allows processes to change the endpoint for speech processing, which attackers can exploit to redirect the authentication token to an external server. This circumvents intended security protocols. Furthermore, the system grants any application or command control over a wide array of undocumented settings, which, in combination with the endpoint manipulation vulnerability, allows attackers to leverage the agent’s privileges to achieve full control over the Muse account. As noted by Patrick Wardle, a macOS security expert who discovered this flaw, the design decisions suggest that developers did not adequately prioritize security from the initial stages of development, which raises significant concerns regarding the assistant’s trustworthiness. Wardle indicated that a simple variation of the ClickFix attack is sufficient for an attacker to seize control of a Muse account, rather than requiring complex malware. This attack can be executed by setting up an attacker’s server as a proxy between the Muse user and Meta’s endpoint, enabling the capture of the authentication token. This complexity is compounded by the fact that Muse was designed to dictate tasks in the cloud, allowing Meta to log the process, and to grant expansive control over system resources through installed applications. Amid these revelations, external reactions occurred, as Amazon began blocking access to Muse, asserting that third-party applications making purchases should adhere to service provider decisions for a secure customer experience, which led to Amazon requesting Meta to remove the agent. Meta released documentation outlining their security design decisions, which surfaced alongside earlier concerns regarding security breaches during internal model testing, prompting dialogue about the pace of AI development. Ultimately, the vulnerability highlights the inherent difficulty in ensuring the security and privacy of AI agents that possess such extensive access to user data and device resources, suggesting that the security posture of such systems remains highly questionable. |