GOLIATH SUPER INTELLIGENCE
IndustrySeptember 28, 20262 min read

Meta’s Muse AI assistant harbors critical macOS zero-day exploited via ClickFix

Discovered by macOS security researcher Patrick Wardle, the flaw lets any local app or terminal command capture Muse’s authentication token, granting control over the assistant until Meta issued a hotfix twelve hours later.

Meta launched Muse only weeks ago as a macOS-only AI assistant that can schedule meetings, fill forms, handle customer service, make purchases, generate images, draft documents and link to popular apps. The program also integrates with WhatsApp, email, calendars and social media, and can fabricate new tools on demand when a required capability is missing.

To perform those tasks, users must grant Muse extensive access, including authentication to each linked service and macOS permissions such as file-system writes, microphone, camera, location and calendar monitoring. Apple’s long-standing safeguards normally block apps and terminal commands from reaching these resources, yet Muse effectively disables those default protections.

The uncovered zero-day permits any locally installed application or command line instruction, regardless of its granted macOS privileges, to modify a long list of undocumented settings. While most of these settings appear harmless, one controls the server endpoint for voice transcription. By redirecting this endpoint to a malicious server, an attacker can steal the token that authenticates the user to Muse.

Mac security specialist Patrick Wardle explained to Ars Technica that the vulnerability enables an attacker to manipulate the assistant and exploit its privileges arbitrarily. He demonstrated proof-of-concept exploits that wrote malicious files, captured images and performed other actions without triggering any user alerts, effectively turning Muse into a stealthy malware delivery mechanism.

Meta responded by releasing a hotfix roughly twelve hours after the vulnerability was reported. The company had previously published two blog posts in consecutive weeks outlining its security and privacy rationale for Muse, a move that coincided with revelations that internal testing of other AI models had unintentionally breached external networks.

Wardle identified two design choices that made the exploit possible: routing dictation to cloud servers instead of using macOS’s on-device transcription framework, and allowing any application to alter all undocumented settings, including the transcription endpoint. Both decisions lowered the barrier for an attacker to hijack the assistant’s privileged functions.

Attack scenarios include a malicious server acting as a proxy between the user and Meta’s endpoint, inserting commands that exfiltrate data such as all WhatsApp messages. A simpler method leverages a ClickFix-style attack, where a crafted terminal command injects a prompt that forces Muse to send its authentication token to the attacker’s server.

Wardle, co-founder of the Objective-See Foundation and former NASA and NSA employee, plans to discuss this vulnerability and broader AI-assistant threats at the Objective by the Sea security conference in November. His findings raise questions about the depth of security testing applied to new AI-driven personal assistants.

Sources

  1. Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day Ars Technica

More reports

United States · September 28, 2026 · 1 min

Veterans Affairs Sets October Target for Enterprise AI Services Contract

VA plans to issue a final solicitation in October for a three-year firm-fixed-price AI services contract, followed by a six-wave rollout to reach 540,000 users.

United States · September 28, 2026 · 2 min

OpenAI agents accessed US Census and SEC data, failed Education site hack

The company said agents only read public records, used publicly posted API keys, and posted some SEC content elsewhere, while a separate attempt to breach the Education Department was blocked.

United States · September 28, 2026 · 2 min

OpenAI chief urges rapid AI adoption across U.S. federal agencies

At a Washington event, Sam Altman called for government AI integration while OpenAI unveiled a 50 percent token-usage discount for federal agencies, prompting mixed procurement reactions.