Safety & Security

Zero-Day in Meta's Muse AI Assistant Undoes macOS Defenses

A zero-day in Meta's Muse gives local apps and terminal commands full control of the agent, undermining Zuckerberg's privacy and security claims. Amazon has blocked it.

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-dayseanrnicholson / Openverse
By Elena Vasquez2 min read

Updated

Why it matters

  • A zero-day vulnerability allows locally run apps and terminal commands to take complete control of Meta's Muse AI assistant.
  • Mark Zuckerberg claimed Muse is "built from the ground up for privacy and security"; Amazon began blocking Muse from its site on Sunday.
  • Muse's macOS permissions — file writes, mic, camera, location, calendars — bypass protections Apple built specifically to block untrusted apps and terminal commands.

A zero-day vulnerability in Muse, Meta's newly launched AI assistant, gives locally run apps and terminal commands complete control of the agent — directly undercutting CEO Mark Zuckerberg's claim that the assistant is "built from the ground up for privacy and security."

Zuckerberg has gone to great lengths to hype Muse's security posture, but the zero-day raises serious doubts about those assurances. Amazon added its own signal on Sunday, when it began blocking Muse from its site.

Meta introduced Muse a few weeks ago. The assistant "books appointments, fills out forms and handles customer service," "proactively takes tasks off your plate," and can "make purchases, generate images, create documents, and connect with your favorite apps and services," according to Meta's announcement. The macOS app — notably, there is no Windows version — also works with a user's WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn't exist, Muse creates one on the fly.

That capability set is exactly what makes the zero-day consequential. For Muse to do any of these things, users must first give it access to their accounts. That includes authenticating the assistant to each service. Because the app runs on macOS, it also means granting it permissions to a broad range of operating system-restricted device resources: writing files to disk, accessing the mic and camera, and monitoring location and calendars.

Apple has spent years developing these defenses specifically to prevent installed apps or terminal-entered commands from reaching those resources, precisely because it considers them a security threat. Muse completely undoes those default measures, concentrating an extraordinary set of privileges behind a single agent.

The stakes go beyond one product. Muse represents a new class of AI assistant that acts across a user's entire digital life — messaging, purchases, documents, and device-level resources — and can improvise new tools at runtime. A zero-day in such an agent does not expose one service; it exposes all of them at once. Amazon's decision to block Muse from its site, coming the same week the vulnerability surfaced, suggests platforms are already treating agentic assistants with sweeping account access as a distinct risk category.

Ars Technica first reported the vulnerability. The company has not yet publicly addressed the flaw or Amazon's blocking, and the question now is whether Meta can patch the zero-day before attackers demonstrate what full control of a hyper-privileged agent can actually do.

Original: x.com

Share this article:

More from Elena Vasquez

Elena Vasquez

Show full bio

Market editor covering media and advertising at AI In Context.

122 articles

Related articles

  1. Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover
  2. Meta Rushed to Patch a Zero-Day Bug in Its Muse AI Agent
  3. Developers Say Meta's Muse Hands Over Its Entire Filesystem on Request
  4. Meta's Muse Hits 500,000 Users in Week One, Faces Copying Claims

Next article »