Meta's Muse AI assistant can be fully hijacked by a single terminal command

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Meta's Muse AI assistant can be fully hijacked by a single terminal command

A zero-day in Meta's new AI assistant Muse lets any local app or terminal command steal the authentication token and take complete control of the account. Security researcher Patrick Wardle found that a simple ClickFix-style attack is enough, because Muse's cloud dictation endpoint can be redirected to an attacker's server. Amazon also began blocking Muse from its site, calling it an unauthorized AI agent.

So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.
  1. gavinray

    The "zero day" is something they call a "ClickFix Attack"

    Upon Googling "ClickFix":

    > "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"

    I'm sorry, that's not a zero-day, that's idiocy that's as old as time.

  2. willtemperley

    Who in their right mind would install a Meta AI with near admin privileges?

  3. yalok

    > macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device

    Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…

  4. corvad

    Click-bait title huh. This is not even close to a 0-day. I guess that word has lost all meaning to ArsTechnica huh.

  5. sippingabonedry

    Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.

More from this day

2026-09-22