Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

A severe security flaw in Muse, Meta’s AI assistant, lets attackers take it over

Meta's Muse AI assistant has a zero-day vulnerability exposing users' account tokens. Zuckerberg's security claims now look hollow.

By mitch·4 min read
A digital assistant face glows on a dark screen amid binary code, evoking a security breach.

Meta’s new AI assistant Muse has a serious security flaw, and the company’s own founder has been bragging about the assistant’s security since the start. Mark Zuckerberg has gone to great lengths to hype the security of Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site.

What Muse Does

Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms and handles customer service,” “proactively takes tasks off your plate,” and can “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly.

The one thing that matters is that users must first give Muse access to their accounts for it to do any of these things. That means authenticating the assistant to each service, and because the app runs on macOS, it also means giving it permissions to a wide range of operating system-restricted device resources such as writing files to disk, accessing the mic and camera, and monitoring location and calendars.

Advertisement

The Security Claim at Issue

Zuckerberg has been boasting about Muse’s security since the beginning. He has said that the assistant is constructed with privacy and security at its foundation. The flaw contradicts that claim.

The Flaw Itself

The token that users authenticate to gain access to their Muse accounts is the core of the vulnerability. Any locally installed app or code running on the machine can take control of it. The assistant was built so that any app or code run on the local machine can change an extensive, undocumented list of settings, without regard for the macOS permissions it holds. Most of those settings are minor — dark mode is one example.

A single setup allows processes to change where transcription occurs. Usually that destination directs to a server run by Meta. An attacker can take advantage of this flaw by altering the location to their own endpoint. Once that change is made, the attacker gains the token that grants complete command over the Muse account.

The Scope of the Problem

The error is grave because it goes beyond a simple data leak or a small issue. It is a core control problem at the heart of Muse’s operation. The assistant is constructed around account access, and the transcription endpoint control setting reveals the token that allows users to log into their Muse account.

That single exposed setting gives attackers complete control over the account.

In real-world terms, an attacker exploiting the flaw can do so by running a custom app or terminal command on the local system, which allows them to:

  • Change the endpoint where transcription occurs
  • Route transcription to their own server
  • Gain the token that controls the entire Muse account
  • Access the user’s WhatsApp, email, calendar, and social media accounts
  • Execute tasks on the user’s behalf

The vulnerability extends beyond a single isolated element; it touches the central authentication token that connects every Muse account, a foundation on which the assistant’s security architecture depends entirely.

What Comes Next

The vulnerability is a serious issue for an assistant that runs locally on macOS and connects to a user’s accounts. It is a serious issue for a company whose founder has been bragging about the assistant’s security. It is a serious issue for anyone who has installed Muse and given it access to their accounts.

Amazon’s block on Sunday suggests the problem has reached a point where even a major retailer is taking action. Whether Meta will acknowledge the flaw, patch it, and re-evaluate Zuckerberg’s security claims remains to be seen.

The point is plain for the moment. When a founder boasts about security and a zero-day flaw surfaces, the boasting ought to be met with doubt until the flaw is corrected.

Key Facts

  • Zero-day vulnerability exposed in Meta’s Muse assistant
  • Attackers can change the transcription endpoint to their own server
  • Gives complete control over the Muse account
  • Amazon began blocking Muse from its site on Sunday
  • No Windows version of the macOS app

Source material: “Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day,” Ars Technica.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.