Meta's Muse AI assistant hit by zero-day letting local apps hijack the agent

Astral Codex Ten · rss · 2026-09-22

Ars Technica reports a zero-day vulnerability in Meta's new macOS AI assistant Muse that gives locally run apps and terminal commands complete control of the agent, undercutting Zuckerberg's claim that it was "built from the ground up for privacy and security." Muse books appointments, fills forms, makes purchases and creates tools on the fly, requiring broad access to WhatsApp, email, calendars, files, mic, camera and location — undoing Apple's default OS protections. Notably there's no Windows version, and Amazon began blocking Muse from its site on Sunday.

Original post →

More from Companies & People

Companies & People channel →