Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Ars Technica Dan Goodin ● Covered by 8 sources
Meta’s Muse AI has a 0-day that gives local apps and terminal commands full control. That’s awkward for something Zuckerberg pitched as built for privacy and security.
Based on reporting by Ars Technica, Dan Goodin — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Meta only introduced Muse a few weeks ago, but the assistant is already in trouble. Mark Zuckerberg has been talking it up as “built from the ground up for privacy and security,” yet a zero-day flaw lets locally run apps and terminal commands take over the agent completely. That is not a small crack in the armor. It is the whole door swinging open.
Muse is meant to do a lot: book appointments, fill out forms, handle customer service, make purchases, generate images, create documents, and connect to other apps and services. On macOS, it can also work with a user’s WhatsApp, email, calendar, and social media accounts. And if it needs a tool it does not already have, it can create one on the fly. That is a lot of reach for a product that only arrived a few weeks ago.
But to do any of that, users have to hand it access first. They authenticate it to each service, then give the app permissions across macOS-protected resources, including the ability to write files, use the mic and camera, and monitor location and calendars. Those protections exist for a reason. Apple built them to keep installed apps and terminal commands away from sensitive parts of the system.
The problem is that Muse appears to undo those default safeguards. The result is hard to square with the security story Meta has been selling. Amazon’s move on Sunday to start blocking Muse from its site only sharpens the point. A tool this ambitious was always going to live or die on trust, and right now it is bleeding it.
My take — AI-written commentary, not fact-checked reporting
This is the part where the AI hype cycle meets ordinary operating-system reality and gets a bruise. If a product needs broad device access, account access, and a live trust fall with the terminal, maybe “built from the ground up for privacy and security” was marketing first and engineering second. Funny how often that happens right before someone blocks it.
Read more about this at: Ars Technica
Related stories
Meta Introduces Muse, a Personal AI Agent That Runs on Its Own Dedicated Secure Cloud Computer
MarkTechPost · 1 week ago ·
42
Meta Launches Muse Code to Rival Claude Code and OpenAI’s Codex
Trending Topics · 1 month ago ·
21