Wednesday, Sep 23, 2026
1 Meta Patches Muse AI Zero-Day Letting Attackers Steal Session TokensMETA π Cybersecurity Sep 23, 9:37 AM EDT 13/9
A security researcher demonstrated that a vulnerability in Meta's Muse AI assistant for Mac could allow unauthorized parties to gain control of the agent and access a user's private files, emails, and messages. The flaw allows malware to modify an undocumented setting to capture prompts or use "ClickFix" to trigger remote code execution via a single Terminal command. Attackers who steal session tokens can control the assistant across multiple devices, enabling them to retrieve an iPhone's precise location and scan for nearby Bluetooth devices.
Meta has since pushed a fix to address the zero-day vulnerability, according to the researcher. A former Meta AI security engineering manager who departed the company in September cautioned against using the assistant, citing deep security and privacy concerns regarding the agent's high level of system privileges.