Zero-day hits Meta's Muse for Mac: local process can steal prompts, auth tokens and file access
MicahBerkley · x · 2026-09-22
A researcher disclosed a zero-day in Meta's new AI agent Muse for Mac: a local process with no special privileges can flip an undocumented Muse setting and exfiltrate dictated prompts to an attacker's server, enabling prompt capture, prompt injection, and theft of Muse's authentication material.
The attack also grants access to whatever the user has let Muse touch — files, Mail, Messages, Calendar, and Notes. The poster jokes it explains why his Muse client randomly logged out.
A Meta AI security engineering manager who left the company this month said the flaw confirms he would never use Muse, citing security and privacy concerns.
Related event: Zero-day in Mac AI assistant Muse can leak prompts and credentials(2 posts)→
More from Models
- Anthropic investigates elevated errors across Claude Mythos 5.1, Fable 5.1 and Opus 5 — ClaudeAI-mod-bot · 2026-09-22
- Dev Swaps Opus for Mimo-v2.6 in Cline on Client Projects: 'It's a Beast' — MicahBerkley · 2026-09-22
- Kev refactored onto Qwen3.5: open-source decision models now at 0.8B, 4B and 9B — alexcovo_eth · 2026-09-22
- Why OpenAI bets on math: it's the most verifiable domain for reinforcement learning — burny_tech · 2026-09-22
- Open-source decision model Laya ported to Core ML: 99.5% ops on ANE, 3.7ms per decision — alexcovo_eth · 2026-09-22
- Fireworks: routing 18 models per task hits 97.6% solve rate at $1.88 vs best single model's 74.1% at $6.52 — sophiamyang · 2026-09-22