← Back to live feed · 1 stories across 1 day
Tuesday, Sep 22, 2026
1 story1 Meta Fixes Muse AI Zero Day That Allowed Control of iPhones From Macs AI Sep 22, 2:34 AM EDT 4/2
The vulnerability permitted a researcher to read chat histories and access an iPhone's location by stealing a session token from a separate Mac. This security hole allowed for the theft of authentication material and the ability to scan for nearby Bluetooth devices using the Muse AI assistant.
Remote access to the agent was possible through ClickFix if a user ran a single Terminal command. This method grants local code execution without any downloads or installations, which enables the hijack of a Muse session on a compromised computer.
Meta pushed a fix for the flaw following the researcher's report, though a former company security engineering manager cited privacy concerns regarding the AI agent. The exploit enabled attackers to modify an undocumented Muse setting to redirect dictation and access user data in Mail, Messages, Calendar, and Notes.