← Back to live feed · 1 stories across 1 day
Tuesday, Sep 22, 2026
1 story1 Meta Patches Zero Day That Let Attackers Hijack Muse AI and Track iPhones AI Sep 22, 7:08 AM EDT 5/3
A security researcher uncovered a zero-day vulnerability in Meta's Muse AI assistant that allows attackers to seize control of the agent and steal session tokens. The flaw enables a local process on Mac with no special privileges to alter an undocumented setting, granting access to the user's files, Mail, Messages, Calendar, and Notes. Attackers can trigger this remotely via a "ClickFix" attack that tricks users into running a single Terminal command to achieve local code execution.
The stolen authentication material allows control over other signed-in devices, including the ability to retrieve an iPhone's exact location and scan nearby Bluetooth devices. Meta pushed a fix for the exploit after the researcher's findings. A former security engineering manager at Meta who departed this month stated he would never use the tool given these privacy and security risks.