# Meta's Muse assistant exposed account-control token through local apps

_Published Monday, September 21, 2026 at 8:09 PM EDT · Security, AI · Latest · Tier 1 — Major_

![Illustration of a robot prying out a locked file. — Primary](https://cdn.arstechnica.net/wp-content/uploads/2026/09/ai-agent-hacking-1152x648.jpg)

A zero-day vulnerability in Meta's Muse assistant lets any locally installed app or terminal command redirect the service's transcription endpoint and capture the token that controls a user's Muse account, Ars Technica reported. The attack does not require the local process to hold the macOS permissions that Muse itself receives.

Muse can access connected email, calendars, social accounts, files, the microphone, camera and location after users authorize it. Redirecting transcription to an attacker-controlled server exposes the authentication token, creating a path to control the assistant account. The report does not identify a patch or mitigation.

## Sources

- [Ars Technica](https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/)

---
Canonical: https://techandbusiness.org/newswire/ei0QTQbmLODXx-DjJOB0Dw
Published: 2026-09-22T00:09:11.053Z
Story chronology: 2026-09-21T22:24:38.000Z
Retrieved: 2026-09-22T02:09:40.407Z
Publisher: Tech & Business (techandbusiness.org)
