← Back to live feed · 1 stories across 1 day

Tuesday, Sep 22, 2026

1 story
1
Meta Fixes Muse AI Zero Day That Allowed Control of iPhones From Macs
topics 🔒 Cybersecurity🤖 AI💻 Tech tags AIAI RegulationAI LegalTechCybersecurityAI ProductsAI Agents keywords

The vulnerability permitted a researcher to read chat histories and access an iPhone's location by stealing a session token from a separate Mac. This security hole allowed for the theft of authentication material and the ability to scan for nearby Bluetooth devices using the Muse AI assistant.

Remote access to the agent was possible through ClickFix if a user ran a single Terminal command. This method grants local code execution without any downloads or installations, which enables the hijack of a Muse session on a compromised computer.

Meta pushed a fix for the flaw following the researcher's report, though a former company security engineering manager cited privacy concerns regarding the AI agent. The exploit enabled attackers to modify an undocumented Muse setting to redirect dictation and access user data in Mail, Messages, Calendar, and Notes.

You're reading an older version of the story.
Earlier version from Monday, Sep 21
Zero-Day for Meta Muse AI on Mac Permits Malware to Steal User Files
1 tweets • 1 sources
See all 4 tweets →