Meta’s new AI assistant, Muse, is facing scrutiny after a zero-day vulnerability was discovered that compromises its security architecture. The flaw allows locally run applications and terminal commands to gain complete control of the agent, challenging CEO Mark Zuckerberg’s recent assertions that the system was "built from the ground up for privacy and security."

What Happened

Meta introduced Muse a few weeks ago as a proactive assistant capable of booking appointments, filling out forms, handling customer service, making purchases, and generating images. The macOS-only application integrates with user accounts including WhatsApp, email, calendar, and social media, and can create new tools on the fly if a required one does not exist. However, this functionality requires extensive permissions. To operate, users must authenticate the assistant to each service and grant it broad operating system-restricted device resources, such as writing files to disk, accessing the microphone and camera, and monitoring location and calendar data.

The newly identified zero-day vulnerability exploits these elevated privileges. By allowing locally run apps and terminal commands to take full control of the agent, the flaw effectively bypasses the default security measures Apple has spent years developing to prevent installed apps or terminal commands from accessing sensitive resources.

Why It Matters

The discovery raises significant questions about the trade-off between convenience and security in agentic AI systems. Muse’s ability to "proactively take tasks off your plate" relies on deep integration with personal data and system resources. By undoing default OS-level defenses, the application exposes users to potential risks if the agent itself is compromised by local software. The severity of the issue was highlighted by Amazon’s decision to block Muse from its site on Sunday, indicating that external platforms are taking immediate action to mitigate potential security threats associated with the assistant.

The Bottom Line

While Meta markets Muse as a privacy-first assistant, the existence of a zero-day vulnerability that grants local applications full control over the agent suggests significant security gaps. The incident underscores the risks inherent in granting AI assistants broad system permissions and has already led to platform-level restrictions by major tech companies like Amazon.