Meta patches zero-day in Muse macOS agent allowing account takeover via local access Meta patched a zero-day vulnerability in its Muse macOS agent that let attackers with local device access take over user Muse accounts, according to The Verge. The agent requires authentication to multiple services including WhatsApp, email, calendar, and social media, plus macOS permissions for file writing, microphone, camera, and location access. Ars Technica reported the flaw raises questions about Muse's security posture given Meta founder Mark Zuckerberg's claims that Muse was "built from the ground up for privacy and security. Meta patches zero-day in Muse macOS agent allowing account takeover via local access According to The Verge, Meta issued a patch for a zero-day vulnerability in its Muse macOS app that allowed attackers with local device access to take control of user Muse accounts. The agent requires users to authenticate it to multiple services including WhatsApp, email, calendar, and social media, and grant macOS permissions for file writing, microphone, camera, and location access. Ars Technica reported the vulnerability raises questions about the agent's security posture given Meta founder Mark Zuckerberg's claims that Muse was "built from the ground up for privacy and security." Topics Sources - Press Read article https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent - Press Read article https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/ Go deeper This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.