Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
A simple ClickFix attack is only one way to completely hijack the new agent.

A simple ClickFix attack is only one way to completely hijack the new agent.
The short version
- Further raising questions, Amazon on Sunday began blocking Muse from its site.
- Meta introduced Muse a few weeks ago.
- When a task requires a tool that doesn’t exist, Muse creates one on the fly.
What happened
“We can manipulate the agent and leverage its privileges to do whatever we want,” Patrick Wardle, the macOS security expert who discovered the zero-day, told Ars. Wardle said that Meta developers made several design decisions that made his exploit possible.
Why it matters
One is the choice for Muse dictation to occur in the cloud, where Meta can log it. macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device.
Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.
