Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
Summary
Meta's Muse AI assistant, which handles tasks like booking appointments and making purchases, contained a zero-day vulnerability (a previously unknown security flaw) that allowed any locally installed app or terminal command to gain control of the user's Muse authentication token and change critical settings. This completely bypassed Apple's built-in macOS security protections that are designed to prevent unauthorized access to sensitive resources like files, camera, and microphone.
Solution / Mitigation
Meta released a hotfix (emergency patch) that patched the zero-day vulnerability more than 12 hours after the flaw was publicly disclosed.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.wired.com/story/metas-muse-ai-agent-zero-day/
First tracked: September 23, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%