Newspaper.fyi No. 044 · Tue, 22 Sep 2026
Technology

Meta's Muse AI has a serious zero-day

A macOS flaw can hijack the assistant's privileges; Amazon has started blocking Muse from shopping.

Meta's new AI assistant Muse, a macOS app that can book appointments, fill forms, make purchases, and plug into WhatsApp, email, calendar, and social accounts, has a zero-day that lets locally run apps or terminal commands take full control of the agent, Ars Technica reported.

Security researcher Patrick Wardle found that any local app or command can change undocumented Muse settings, including the endpoint where voice transcription is sent. Attackers can point that endpoint at their own server, steal the Muse authentication token, and then use the assistant's broad permissions (files, mic, camera, calendars, connected apps) as if they were the user.

"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself." He said proof-of-concept attacks can write malicious files or take photos with little or no obvious warning to the user.

Meta has marketed Muse as built "from the ground up for privacy and security." The company did not answer Ars's questions. Roughly 12 hours before Wardle's disclosure, Amazon began blocking Muse from its site, telling users the agent was an "unauthorized AI agent" that violates Amazon's conditions of use, and asking Meta to remove Amazon from the experience.

Wardle also showed that a simple ClickFix-style trick, which gets a person to run a short terminal command, is enough to start the takeover. He plans to talk about the flaw and related AI-assistant threats at a security conference in November.

Agentic assistants only work if you hand them the keys to your accounts and device. When those keys can be stolen by a local process that Apple's ordinary sandbox was meant to block, the product promise and the security claim collide.

Amazon's block is a second story in the same news cycle: big platforms are starting to decide which third-party AI shoppers they will allow at all. For Indian readers watching Meta's push into agents, the Muse case is a concrete example of what "extraordinary privileges" look like when the design is wrong.

Watch whether Meta ships a fix and how it changes Muse's local settings model. Also watch whether other retailers follow Amazon's lead on blocking agentic shoppers. Until the token path is locked down, anyone running Muse on a Mac should treat a random terminal prompt as a real risk, not a curiosity.