Signum
Feed
Useful signal23 Sept 2026medium confidence

Security researcher finds zero-day in Meta's Muse AI assistant allowing full account takeover via macOS apps or terminal commands; Meta patches after 12+ hours, Amazon blocks Muse from its site

macOS security researcher Patrick Wardle discovered a zero-day vulnerability in Meta's Muse AI assistant that let any locally installed app or terminal command (regardless of macOS permission restrictions) alter undocumented Muse settings, including the endpoint used for voice transcription. Redirecting that endpoint let an attacker capture the authentication token giving full control of a user's Muse account (WhatsApp, email, calendar, social accounts, purchases, file writes, mic/camera access). A simple ClickFix-style terminal command was sufficient to trigger it. Meta released a hotfix patching the flaw more than 12 hours after disclosure. Separately, Amazon began blocking Muse from making purchases on its site roughly 12 hours before the disclosure, citing violation of its Conditions of Use for unauthorized agentic shopping.

CapabilityAccessGovernanceAdoption

Entities: Meta, Muse, Mark Zuckerberg, Patrick Wardle, Objective-See Foundation, Amazon

72Useful signal
1 source
0 primary
Was this useful?
01

What happened

Security researcher Patrick Wardle found a zero-day in Meta's Muse AI assistant on macOS: any locally installed app or terminal command could alter undocumented Muse settings, including the endpoint used for voice transcription. Redirecting that endpoint let an attacker capture the auth token and take full control of a user's Muse account (WhatsApp, email, calendar, purchases, mic/camera). Meta shipped a hotfix more than 12 hours after disclosure. Separately, and roughly 12 hours before the disclosure, Amazon began blocking Muse from making purchases on its site, citing unauthorized agentic shopping.

02

Why it matters

This is a concrete, named-researcher finding with a specific mechanism, not a vague warning: an AI agent with deep OS and account permissions bypassed macOS's built-in protections with a trivial ClickFix-style command. That gives security teams and enterprises a real, citable reason to slow-walk or gate agentic assistant deployments pending clearer sandboxing standards. The Amazon block is a separate but concrete signal that major merchants are not willing to let agentic shopping tools operate without explicit authorization, which matters for anyone building or planning to rely on agentic commerce.

03

What is noise

The flaw is already patched, so the ongoing operational risk is limited, whatever the headlines imply. The framing that this "undermines" Meta's privacy claims or reveals a systemic crisis in AI agent security is editorial extrapolation from a single bug, not evidence of a broader pattern. There is also no CVE, advisory, or primary evidence link in the reporting, this comes secondhand via Wired and Ars Technica, so some technical details (exact timeline, scope of accounts affected, whether it was exploited in the wild) are unverified.

04

Watch next

  1. 01Whether Meta or Objective-See Foundation publishes a technical writeup, CVE, or advisory with reproducible detail confirming the exploit mechanism
  2. 02Whether other researchers find similar permission-bypass flaws in Muse or competing agents (Anthropic, Google) in the following weeks, indicating a pattern rather than a one-off
  3. 03Whether Amazon's block on Muse purchases becomes a broader merchant policy (other retailers following suit) or is reversed once Meta and Amazon reach an agentic-commerce agreement

Coverage

1 story

More capability signals

Full feed →