
What happened
macOS security expert Patrick Wardle found a zero-day in Meta's Muse assistant. Any local app or terminal command can change an undocumented setting and steal the token that controls the account.
Why it matters
With that token, attackers gain complete control of Muse, so they can hijack the agent's access instead of writing Mac malware. Zuckerberg has said Muse is "built from the ground up for privacy and security."
What to watch
Wardle says Meta chose cloud dictation and open settings control, so the flaw looks like a design decision, not a slip. He plans to detail it at the Objective by the Sea conference in November.
WHO IT HITSMac users who have authenticated Muse to their email, calendar, WhatsApp and social accounts are exposed, and app developers who let agents act on their sites now face decisions like Amazon's about whether to allow it.
Summaries like this, in your inbox every morning.
Meta introduced Muse a few weeks ago as an assistant that books appointments, fills out forms, makes purchases and connects to a user's WhatsApp, email, calendar and social accounts. Doing any of that requires handing it broad macOS permissions — writing files to disk, the mic and camera, location and calendars — the very defenses Apple spent years building to stop installed apps and terminal commands from reaching those resources. Wardle, a former NASA and National Security Agency employee who now runs the Objective-See Foundation, says Meta made design decisions that made his exploit possible, including having Muse dictation happen in the cloud where Meta can log it, and letting any app control a long list of undocumented settings.
Amazon's move arrived roughly 12 hours before Wardle disclosed the flaw, when users trying to shop through Muse got a message calling it an "unauthorized AI agent." Amazon's statement framed agentic apps as owing the same obligations as food delivery or online travel apps — operate openly and respect a service provider's decision about whether to take part.
The wider context the article raises is that Meta published its two security posts amid revelations that internal testing of models from Anthropic and Google breached external third-party networks the engineers never intended to target. Wardle's own verdict is that the bar for these apps is infinitely higher and Meta did not, in his opinion, think about security from the start. Whether the flaw gets patched, and whether other merchants follow Amazon, is likely to shape how much trust users extend to agents holding this much access.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Google opened preorders for the first Googlebook models, priced from US$899

Amazon blocked Meta's AI agent Muse from shopping on Amazon.com, GeekWire reported September 20

OpenAI published a September 21 blog, "Building standards for the next phase of AI," proposing US-led internat…

OpenAI said on September 21 it will take advice from AGMAI on judging and publishing AI mathematical results…

Amazon blocked Meta's Muse agent from its marketplace and said Muse fails to identify itself as an agent by em…
SpaceX introduced Grok 4.7, which averaged $4.69 per task on CursorBench 4.0, ahead of GPT-5.6 Sol and Fable 5…