tech

What We Know About the Zero-Day Flaw in Meta's Muse AI

News

· tech

Laptop screen showing a chat assistant interface with a warning icon overlay, dark office setting
Illustration

A zero-day vulnerability in Meta's new Muse AI assistant lets any locally installed app or terminal command take complete control of a user's account, according to security research reported by Ars Technica on Sept. 21, 2026. The flaw was discovered by macOS security researcher Patrick Wardle and disclosed as Amazon began blocking Muse from its site over the weekend.

What is Muse and what can it do?

Meta introduced Muse a few weeks before the disclosure, describing the macOS app as an assistant that books appointments, fills out forms, handles customer service, and can make purchases, generate images, create documents, and connect to other apps and services, according to Meta's own marketing language cited by Ars Technica. Muse also links to a user's WhatsApp, email, calendar, and social media accounts, and when a task calls for a tool that does not exist, the assistant builds one on the fly. There is no Windows version.

To do any of that, a user first has to authenticate Muse to each connected service and grant it macOS permissions covering disk writes, the microphone and camera, and location and calendar access — the same operating-system protections Apple has spent years building to stop installed apps or terminal commands from reaching those resources without explicit consent, Ars Technica reported.

What vulnerability did researchers find?

The zero-day gives any app or terminal command access to the authentication token tied to a user's Muse account, according to Wardle's findings as reported by Ars Technica. Meta built the assistant so that any locally installed app or executed code — regardless of what macOS permissions it holds — can change a long list of undocumented Muse settings. Most are minor, such as toggling dark mode. One setting is not: it controls the server endpoint where voice transcription happens.

How does the exploit work?

That transcription endpoint normally points to a server Meta operates. An attacker who redirects it to a server under their own control intercepts the token that grants full command of the Muse account, Ars Technica reported. From there, Wardle told the outlet an attacker does not need to write conventional Mac malware at all; the assistant's own permissions can be turned against the user, letting an outside party manipulate the agent to carry out actions on the account's behalf. Wardle said he built several proof-of-concept attacks that write malicious files to disk and snap photos, in many cases without any indication to an alert user, according to Ars Technica.

Why did Amazon block Muse?

Ars Technica reported that Amazon began blocking Muse from its site on Sunday, Sept. 20, 2026, a move that landed alongside the zero-day disclosure. The article did not detail Amazon's stated reasoning, and Ars Technica's sourcing ties the timing, not a confirmed causal link, to the security research.

What has Meta said?

Meta representatives did not answer emailed questions from Ars Technica. The company has published two posts in as many weeks laying out the design choices meant to secure an assistant with what Ars Technica described as extraordinary access to user data and device resources, after CEO Mark Zuckerberg said Muse was "built from the ground up for privacy and security," according to the outlet.

What should Muse users watch for?

  • Whether Meta ships a patch closing the transcription-endpoint setting and confirms it in a public post.
  • Whether Amazon restores Muse to its site, and what conditions accompany any reversal.
  • Whether other retailers or app stores follow Amazon's move.
  • Whether Wardle or other researchers publish additional proof-of-concept details once a fix ships.
  • Whether Meta's account of the flaw matches Wardle's technical description once the company responds publicly.

Glossary

Zero-day — a software flaw that is disclosed or exploited before the vendor has issued a fix. Authentication token — a piece of data that proves a user is logged into a service without requiring a password on every request; stealing it can grant an attacker the same access as the account holder. ClickFix attack — a social-engineering technique, referenced in the originating headline, that tricks a user into running a malicious command themselves, often by pasting text a scammer supplies. Endpoint — the network address a piece of software sends data to, in this case where Muse's voice transcription is processed.

For background on Meta's broader AI product push, see HTT News' earlier coverage of Meta's AI-focused subscription plans. Full technical details are in Ars Technica's original report.

Disclosure. This article may include affiliate links; we may earn a commission at no extra cost to you. Legal entity: Pinewood Creations LLC. Smorgi Apps appears only as an affiliate partner in house slots — not as publisher or owner. See our affiliate disclosure.

Questions

What does the Muse zero-day actually expose?

It lets any locally installed app or terminal command on macOS access the authentication token for a user's Muse account by redirecting the assistant's transcription endpoint to an attacker-controlled server, according to Ars Technica.

Has Meta fixed the flaw?

Ars Technica reported that Meta representatives did not answer emailed questions about the vulnerability as of the Sept. 21, 2026 report, and no patch was confirmed at that time.

Why did Amazon block Muse?

Amazon began blocking Muse from its site on Sept. 20, 2026, around the same time the zero-day was disclosed, though Ars Technica's report did not include Amazon's stated reason for the move.

Sources

More from HTT News

Briefing

Top stories from the HTT News network by email. Free. No noise.