← All news·2026-09-23·3 min read

Meta's Muse AI Assistant Had a Zero-Day on macOS

Security researcher Patrick Wardle found a zero-day in Meta's Muse AI assistant for macOS that gave full control of the account, including WhatsApp, email and purchases. Meta shipped a hotfix about 12 hours later.

aimetaбезопасностьагенты

Security researcher Patrick Wardle found a zero-day vulnerability in Meta's Muse AI assistant on macOS. Through it, any local app or terminal command can redirect the address where Muse sends the user's voice recording, capture the account access token and gain full control of the account, including access to WhatsApp, email, calendar and purchases the user granted to the assistant. A single command using a ClickFix-style attack is enough, and Meta shipped a hotfix about 12 hours after the report went public.

This shows the real cost of agents with broad access: the more services are connected, the more expensive one permission hole becomes, and Muse's developers left exactly the channel carrying the user's voice unprotected. I work with agents in Claude Code every day, and for me the question is never whether an agent can reach a service, it is who checks what access it actually gets. A 12-hour hotfix is fast, but the people who had already connected personal accounts before the patch already paid the price.

Source: arstechnica.com

Free course

Stop reading about AI — start building with it

The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.

Start free →
EAEvgenii Arsentev

Author

Evgenii Arsentev

PhD · Chief Executive Officer, digital health