Zero-day hits Meta's Muse for Mac: local process can steal prompts, auth tokens and file access

MicahBerkley · x · 2026-09-22

A researcher disclosed a zero-day in Meta's new AI agent Muse for Mac: a local process with no special privileges can flip an undocumented Muse setting and exfiltrate dictated prompts to an attacker's server, enabling prompt capture, prompt injection, and theft of Muse's authentication material.

The attack also grants access to whatever the user has let Muse touch — files, Mail, Messages, Calendar, and Notes. The poster jokes it explains why his Muse client randomly logged out.

A Meta AI security engineering manager who left the company this month said the flaw confirms he would never use Muse, citing security and privacy concerns.

Related event: Zero-day in Mac AI assistant Muse can leak prompts and credentials(2 posts)→

Original post →

More from Models

Models channel →