E-Ink News Daily

Back to list

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

A serious zero-day vulnerability in Meta's Muse AI assistant allows any locally running app or terminal command to steal the authentication token controlling the agent, giving attackers complete control over users' accounts and data. Amazon has begun blocking Muse from its site following the disclosure, adding to concerns raised by the vulnerability's severity.

Background

Meta launched its Muse AI assistant on macOS, positioning it as a privacy-focused personal assistant that accesses users' calendars, WhatsApp, email, and other services. The assistant requires extensive system permissions to function, making any credential theft vulnerability particularly dangerous.

Source
Ars Technica
Published
Sep 22, 2026 at 06:24 AM
Score
8.0 / 10