Security researchers find zero-day flaw letting local apps and terminal commands hijack Meta's Muse AI assistant; Amazon begins blocking Muse
A zero-day vulnerability was disclosed in Meta's Muse macOS AI assistant that allows locally run apps and terminal commands to gain complete control of the agent, bypassing macOS's permission protections that Muse was granted (file writes, mic/camera, location, calendar access, and connected accounts like WhatsApp, email, social media). Separately, Amazon began blocking Muse from its site starting Sunday.
Entities: Meta, Muse, Mark Zuckerberg, Amazon, Apple, macOS
0 primary
What happened
Security researchers disclosed a zero-day vulnerability in Muse, Meta's macOS AI assistant, that lets locally run apps and terminal commands seize full control of the agent, bypassing the macOS permissions Muse had been granted (file writes, microphone, camera, location, calendar, and linked accounts such as WhatsApp and email). Separately, Amazon began blocking Muse from its site from Sunday. The report comes from Ars Technica; no CVE number, vendor advisory, proof-of-concept, or affected version range has surfaced yet.
Why it matters
If accurate, this is a real attack surface issue: any local app or script on a compromised or malicious-adjacent Mac could hijack an assistant with access to a user's calendar, messages, email and social accounts, not just a theoretical privacy concern. Security teams evaluating Muse or similar OS-level AI agents have a concrete reason to delay deployment or restrict permissions until Meta patches and confirms scope. The Amazon block is a useful external signal that a third party independently judged Muse risky enough to act on, though the report does not establish that Amazon's move was caused by this specific flaw.
What is noise
The framing that this "undermines Zuckerberg's privacy claims" is editorial commentary, not new evidence, and the vulnerability report and the Amazon blocking are presented together without a shown causal link. Key details needed to judge severity are missing: no CVE, no researcher writeup or PoC, no disclosure timeline, no affected macOS or Muse version, and no confirmation Meta has acknowledged or patched it. Treat this as a single secondary-source account until primary documentation appears.
Watch next
- 01A CVE assignment or a vendor security advisory from Meta confirming the flaw and listing affected versions
- 02A published researcher writeup or proof-of-concept demonstrating the exploit in detail
- 03Confirmation of whether Amazon's blocking of Muse is explicitly tied to this vulnerability or a separate policy decision, and whether other platforms (browsers, app stores) follow suit
Coverage
1 storyMore capability signals
Full feed →- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- Anthropic threat report: Claude abused for malware, drone/missile software, mass surveillance, and industrial-scale distillation by Chinese AI labs11 Sept 202680
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680
- Google DeepMind launches AlphaGenome Atlas, a free public database of predicted effects for 9 billion possible human genome variants8 Sept 202679