Security researcher finds zero-day in Meta's Muse AI assistant allowing full account takeover via macOS apps or terminal commands; Meta patches after 12+ hours, Amazon blocks Muse from its site
macOS security researcher Patrick Wardle discovered a zero-day vulnerability in Meta's Muse AI assistant that let any locally installed app or terminal command (regardless of macOS permission restrictions) alter undocumented Muse settings, including the endpoint used for voice transcription. Redirecting that endpoint let an attacker capture the authentication token giving full control of a user's Muse account (WhatsApp, email, calendar, social accounts, purchases, file writes, mic/camera access). A simple ClickFix-style terminal command was sufficient to trigger it. Meta released a hotfix patching the flaw more than 12 hours after disclosure. Separately, Amazon began blocking Muse from making purchases on its site roughly 12 hours before the disclosure, citing violation of its Conditions of Use for unauthorized agentic shopping.
Entities: Meta, Muse, Mark Zuckerberg, Patrick Wardle, Objective-See Foundation, Amazon
0 primary
What happened
Security researcher Patrick Wardle found a zero-day in Meta's Muse AI assistant on macOS: any locally installed app or terminal command could alter undocumented Muse settings, including the endpoint used for voice transcription. Redirecting that endpoint let an attacker capture the auth token and take full control of a user's Muse account (WhatsApp, email, calendar, purchases, mic/camera). Meta shipped a hotfix more than 12 hours after disclosure. Separately, and roughly 12 hours before the disclosure, Amazon began blocking Muse from making purchases on its site, citing unauthorized agentic shopping.
Why it matters
This is a concrete, named-researcher finding with a specific mechanism, not a vague warning: an AI agent with deep OS and account permissions bypassed macOS's built-in protections with a trivial ClickFix-style command. That gives security teams and enterprises a real, citable reason to slow-walk or gate agentic assistant deployments pending clearer sandboxing standards. The Amazon block is a separate but concrete signal that major merchants are not willing to let agentic shopping tools operate without explicit authorization, which matters for anyone building or planning to rely on agentic commerce.
What is noise
The flaw is already patched, so the ongoing operational risk is limited, whatever the headlines imply. The framing that this "undermines" Meta's privacy claims or reveals a systemic crisis in AI agent security is editorial extrapolation from a single bug, not evidence of a broader pattern. There is also no CVE, advisory, or primary evidence link in the reporting, this comes secondhand via Wired and Ars Technica, so some technical details (exact timeline, scope of accounts affected, whether it was exploited in the wild) are unverified.
Watch next
- 01Whether Meta or Objective-See Foundation publishes a technical writeup, CVE, or advisory with reproducible detail confirming the exploit mechanism
- 02Whether other researchers find similar permission-bypass flaws in Muse or competing agents (Anthropic, Google) in the following weeks, indicating a pattern rather than a one-off
- 03Whether Amazon's block on Muse purchases becomes a broader merchant policy (other retailers following suit) or is reversed once Meta and Amazon reach an agentic-commerce agreement
Coverage
1 storyMore capability signals
Full feed →- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- OpenAI launches GPT-6 Sol and Luna at half the token price of GPT-5.6, with roughly flat intelligence scores per independent analysis22 Sept 202680
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680