Skip to content
Tech News
← Back to articles

Meta's Muse AI Assistant Launched With Zero-Day Flaw Exposing Auth Tokens

read original more articles
GoKawiil Brief

Security researchers found a zero-day vulnerability in Meta's newly released Muse AI assistant for macOS that lets any locally installed app or terminal command access the token authenticating a user's Muse account, along with a long list of undocumented settings. Amazon has begun blocking Muse on its site, and the flaw undermines macOS permission protections that Apple built to prevent unauthorized apps from reaching sensitive resources like the microphone, camera, and file system.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The flaw is notable because Zuckerberg publicly touted Muse as 'built from the ground up for privacy and security,' a claim this vulnerability directly contradicts. Since Muse connects to WhatsApp, email, calendars and other accounts, a compromised auth token could let malicious local processes hijack those linked services, suggesting the assistant's broad permissions create outsized risk if exploited. Amazon's move to block the app may signal that other companies see similar security concerns, though the reasoning behind that decision hasn't been confirmed.

Key Takeaways

Source: wired.com — Dan Goodin, 2026-09-23

Published there as: “Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.