Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
A simple ClickFix attack is only one way to completely hijack the new agent.

TL;DR
- A zero-day vulnerability in Meta's AI assistant Muse allows any locally run app or terminal command to gain complete control of the agent.
- The flaw enables attackers to change Muse's transcription endpoint to their own server, stealing authentication tokens and gaining full access.
- macOS security expert Patrick Wardle discovered the vulnerability, demonstrating that a simple ClickFix attack can exploit it.
- Amazon has begun blocking Muse from its site, stating it violates their Conditions of Use for unauthorized AI agents making purchases.
- Wardle criticizes Meta's design decisions, suggesting a lack of security considerations in Muse's development.
- The vulnerability arises from Muse's cloud-based dictation and its allowance for any app to control undocumented settings, including sensitive ones.