📣 Send us your press release
Site updates every 15 minutes
Technology

Meta's AI Assistant Muse Reveals Major Zero-Day Vulnerability

Meta's new AI assistant, Muse, has been found to have a critical zero-day vulnerability allowing full control by local apps and commands. Amazon has also begun blocking Muse from its site.

21 September 2026
Meta's AI Assistant Muse Reveals Major Zero-Day Vulnerability

Meta's new artificial intelligence assistant, Muse, has been discovered to possess a critical zero-day vulnerability. This flaw allows locally run applications and terminal commands to gain complete control over the AI. The finding casts significant doubt on Meta's claims that Muse was "built from the ground up for privacy and security." Adding to the concerns, Amazon reportedly began blocking Muse from its site on Sunday.

Muse, introduced by Meta a few weeks ago, is designed to handle tasks such as booking appointments, filling out forms, and managing customer service. It can also make purchases, generate images, create documents, and connect with users' favorite apps and services. The macOS application integrates with users' WhatsApp, email, calendar, and social media accounts, and can dynamically create tools for tasks it doesn't have existing functionalities for.

For Muse to perform its functions, users must grant it access to their accounts and various operating system resources. This includes permissions for file writing, microphone and camera access, and monitoring of location and calendars. These permissions bypass Apple's built-in security measures designed to protect user data from unauthorized access, raising further questions about the AI's security posture.

Original source: arstechnica.com