{"data":{"id":"fee8c3b7-c7b2-46c3-9c74-4d2f7b28d521","title":"Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw","summary":"Meta's Muse AI assistant, which handles tasks like booking appointments and making purchases, contained a zero-day vulnerability (a previously unknown security flaw) that allowed any locally installed app or terminal command to gain control of the user's Muse authentication token and change critical settings. This completely bypassed Apple's built-in macOS security protections that are designed to prevent unauthorized access to sensitive resources like files, camera, and microphone.","solution":"Meta released a hotfix (emergency patch) that patched the zero-day vulnerability more than 12 hours after the flaw was publicly disclosed.","labels":["security"],"sourceUrl":"https://www.wired.com/story/metas-muse-ai-agent-zero-day/","publishedAt":"2026-09-23T12:54:58.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":["Meta"],"affectedVendorsRaw":["Meta","Muse","Amazon","Anthropic","Google"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-23T12:54:58.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}