Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day
Summary
Muse, Meta's AI assistant, has a zero-day vulnerability that allows locally run apps and terminal commands to hijack the agent by altering the transcription endpoint and authenticating tokens. The flaw highlights security design weaknesses in AI agents with broad access, and resulted in Amazon blocking Muse. The report includes insights from security researcher Patrick Wardle and Meta's security notes, emphasizing the need for stronger security practices when deploying AI-enabled tools.