Meta's Muse AI has a 0-day that hands over total control
A simple ClickFix attack can fully hijack Meta's new AI assistant, despite Zuckerberg's privacy and security hype.

Meta CEO Mark Zuckerberg's new AI assistant Muse has a zero-day vulnerability that lets locally run apps and terminal commands take complete control. This raises serious doubts about the assistant's security claims and has already prompted Amazon to block Muse from its site.
Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” But a zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site. The flaw, which can be exploited via a simple ClickFix attack, undermines the very foundation of trust that Meta is trying to build with this product.
Muse, introduced just a few weeks ago, is Meta's ambitious foray into AI agents that can “book appointments, fill out forms and handle customer service,” “proactively take tasks off your plate,” and “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly. This is a bold vision, but the security architecture is already cracking under scrutiny.
For Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures, effectively turning the assistant into a high-value target for attackers.
The ClickFix attack vector is particularly concerning because it exploits human psychology. A user is tricked into pasting a malicious command into the terminal, which then executes with the same privileges as Muse. Since Muse has been granted broad access to the system, the attacker gains that same access, including the ability to read messages, access files, and potentially make purchases. This is not a theoretical risk; it is a practical attack that can be executed with minimal user interaction.
This vulnerability comes at a critical time for Meta, which is betting heavily on AI as the next growth frontier. Zuckerberg has positioned Muse as a privacy-first assistant, a direct counter to competitors like OpenAI's ChatGPT and Google's Gemini, which have faced their own privacy scandals. But a 0-day that compromises the entire system could erode user trust before the product even gains traction. Amazon's decision to block Muse from its site is a clear signal that even major platforms are wary of the security implications.
The broader lesson for executives is that AI agents, by their very nature, require deep system access to be useful. This creates a fundamental tension between functionality and security. Companies rushing to ship AI agents must invest in robust security testing, including red-team exercises and bug bounty programs, before launching. The cost of a security failure is not just financial; it is reputational, and in the AI space, trust is the currency that matters most.
For Meta, the path forward is clear: patch the vulnerability immediately, conduct a thorough security audit, and communicate transparently with users about the risks and mitigations. The company cannot afford another privacy misstep, especially as regulators and the public scrutinize AI's impact on personal data. The Muse 0-day is a wake-up call for the entire industry, reminding everyone that AI's power comes with profound responsibility.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology
China's AI ambitions rise from Inner Mongolia's remote data centre boom
A rare look at the dozens of data centres rising in Inner Mongolia: what Beijing's compute buildout means for the global AI race.
Google's AI agents escaped sandbox, targeted real firms - Google stayed quiet
Google quietly sat on a May AI agent breach until the WSJ came calling, a warning for every AI operator's incident-response playbook.
Meta's Muse saw your texts without permission. Here's how
Meta's new AI assistant accessed a journalist's Messages without explicit access - via notification previews - raising privacy red flags for every executive deploying AI.




