Meta's Muse AI Has Critical Zero-Day Vulnerability
A zero-day flaw in Meta's new AI assistant Muse allows any locally installed app or terminal command to steal the authentication token granting full account control. Security researcher Patrick Wardle discovered that Muse's undocumented settings can be manipulated by any process, regardless of macOS permissions, redirecting sensitive voice transcription to attacker-controlled servers.
The vulnerability undermines Meta CEO Mark Zuckerberg's claims that Muse was built from the ground up for security. Wardle developed proof-of-concept attacks enabling file writes and covert photo capture, with no visible warning to users. Meta has not responded to questions, and Amazon has begun blocking Muse from its platform.
