Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
CybersecurityComputer Science
THE AI ANGLE
Executing system-level tasks and managing personal user accountsSecurity researcher Patrick Wardle discovered a zero-day flaw in Meta's macOS AI assistant, Muse. Unprivileged local code can alter the assistant's transcription endpoint, steal its authentication token, and hijack its broad system permissions. The exploit demonstrates how personal AI agents create new attack paths that bypass established operating system boundaries.
THE TEACHING ANGLE
Discuss whether granting an AI assistant broad device permissions undermines traditional operating system access controls.Read the original at arstechnica.com Generate teaching or study materials
More in Cybersecurity
- Hackers are hiding malware on blockchains that are nearly impossible to take down, and unrestricted AI models have pushed these attacks up 440%TechRadar · September 22, 2026
- GPT-6 Astra Breaks an Old Enigma MessageSchneier on Security · September 22, 2026
- Samsung and LG vow to remove 'botnet' apps from their smart TV app stores that turned sets into an AI scraping machines — but the shocking claim that over 40% of webOS apps had botnet code raises the question of how things ever got this badTechRadar · September 21, 2026
- The AI models that cheat the most, according to new CAIS benchmarkZDNet · September 21, 2026
- Should AI have the same data access restrictions as employees?CIO.com · September 21, 2026