← Back to live feed

Tuesday, Sep 22, 2026

1
Meta Patches Zero Day That Let Attackers Hijack Muse AI and Track iPhonesMETA
topics 🔒 Cybersecurity🤖 AI💻 Tech tags TechCybersecurityAIAI RegulationAI Legal META keywords

A security researcher uncovered a zero-day vulnerability in Meta's Muse AI assistant that allows attackers to seize control of the agent and steal session tokens. The flaw enables a local process on Mac with no special privileges to alter an undocumented setting, granting access to the user's files, Mail, Messages, Calendar, and Notes. Attackers can trigger this remotely via a "ClickFix" attack that tricks users into running a single Terminal command to achieve local code execution.

The stolen authentication material allows control over other signed-in devices, including the ability to retrieve an iPhone's exact location and scan nearby Bluetooth devices. Meta pushed a fix for the exploit after the researcher's findings. A former security engineering manager at Meta who departed this month stated he would never use the tool given these privacy and security risks.

Continued in
Meta Patches Muse AI Zero-Day Letting Attackers Steal Session Tokens
13 tweets • 9 sources
Earlier version from Tuesday, Sep 22
Meta Fixes Muse AI Zero Day That Allowed Control of iPhones From Macs
4 tweets • 2 sources
See all 5 tweets →