Meta's Muse AI assistant shipped with a zero-day giving attackers full Mac control

nordicinst · x · 2026-09-23

Per WIRED/Ars Technica, Meta's new AI assistant Muse launched weeks ago with a zero-day vulnerability letting locally run apps and terminal commands take complete control of the agent — attackers could do "whatever" they wanted on a victim's Mac. Muse books appointments, fills forms, makes purchases and connects to WhatsApp, email and calendar, requiring broad macOS permissions and even creating tools on the fly. Zuckerberg had touted Muse as "built from the ground up for privacy and security"; Meta says it has issued a fix, and Amazon began blocking Muse from its site. The incident underscores the inherent risks of AI agents with sweeping system access.

Related event: Meta's Mac AI Assistant Muse Hit by Zero-Day Allowing Full Takeover(7 posts)→

Original post →

More from Safety

Safety channel →