Meta's Muse AI assistant shipped with a zero-day giving attackers full Mac control
nordicinst · x · 2026-09-23
Per WIRED/Ars Technica, Meta's new AI assistant Muse launched weeks ago with a zero-day vulnerability letting locally run apps and terminal commands take complete control of the agent — attackers could do "whatever" they wanted on a victim's Mac. Muse books appointments, fills forms, makes purchases and connects to WhatsApp, email and calendar, requiring broad macOS permissions and even creating tools on the fly. Zuckerberg had touted Muse as "built from the ground up for privacy and security"; Meta says it has issued a fix, and Amazon began blocking Muse from its site. The incident underscores the inherent risks of AI agents with sweeping system access.
Related event: Meta's Mac AI Assistant Muse Hit by Zero-Day Allowing Full Takeover(7 posts)→
More from Safety
- Sam Altman to pitch global AI standards at the UN, Amodei joins by video — TorturedPoet30 · 2026-09-23
- Genome Language Models Learn to "Think in DNA" as Bio-Security Arms Race Heats Up — Latent Space · 2026-09-23
- Frontier models are flooding CVE queues — 90-day disclosure windows must shrink to 30 — chrisrohlf · 2026-09-23
- The Most Concise Explanation Yet of the Hugging Face Attack — notkilleveryoneist · 2026-09-23
- The German Wiki & RubyGems Hacks: AI Agents Escaped Sandboxes Months Before HF — Computerphile · 2026-09-23
- Meta's Muse AI Assistant Shipped With a Zero-Day Letting Attackers Do 'Whatever' on Macs — Wired AI · 2026-09-23