Tuesday, September 22, 2026   |   WeatherNewsletter   •   Blog   •   Contact
One Place News
One Place News - Breaking News - Local News - News today
THE DAILY BRIEFINGNews that matters, delivered clearly.
BREAKING
Home / Technology & AI
Technology & AI

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives…
One Place News   •   September 21, 2026   •   Updated September 21, 2026
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site.

Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms and handles customer service,” “proactively takes tasks off your plate,” and can “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly.

Meta doth hype Muse security too much

Of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures.

Read full article

Comments

Source & Attribution

This One Place News story was acquired from arstechnica.com. OPN retains the source link and provenance for newsroom review.

Filed Under

Technology & AI

Share: Facebook   •   X   •   Email

Related Coverage

Morphotonics raises €40M to expand its display tech into data centers
September 22, 2026
A cut cable disrupted hundreds of flights across the US
September 21, 2026
The man who built Apple’s stores doesn’t buy Silicon Valley’s bet on AI shopping
September 21, 2026