Meta Muse AI Agent Zero Day One Click Exploit - AI Will Destroy Normies
Dan PetersonSynopsis — AI-drafted from Dan's notes
A 40-minute “story time” built on Dan Goodin’s Ars Technica report about a zero-day in Muse, Meta’s agent for the Mac. Eli starts with a meetup at All Things Open in the Research Triangle. A speaker had just shown off coding tools with shell access, and when Eli asked whether there was a modern Active Directory to stop an agent wiping production, the answer was “well, you trust your developers, don’t you?” His reply is the thesis: trust nobody, yourself least of all, because the most dangerous finger in technology is your own. With agents, many entities act under one login, and permissions tied to the user account no longer tell you who did what.
Then the vulnerability. Muse fills forms, books appointments, makes purchases, and connects to WhatsApp, email, calendar and social accounts. On the Mac, users grant it the operating system’s protected resources as well. Patrick Wardle found that any local app or terminal command, whatever its own permissions, could rewrite an undocumented Muse setting: the endpoint where voice dictation is sent. Point it at an attacker’s server and the account token goes with it. A proxy can then inject its own prompts, in Wardle’s demo exporting the user’s WhatsApp archive. The delivery is a ClickFix lure, the “paste this into Terminal” fix from a forum, which is how Eli pictures normal users getting caught. Wardle’s line, “we can just leverage the AI assistant itself,” is the video’s centre: the attacker doesn’t write a stealer, because the agent already is one. Eli adds that Amazon began blocking Muse from its store the same weekend.
The rest is his argument against agentic AI in general. Every feature is attack surface, and an agent that writes its own tools on the fly is unbounded surface. The frontier labs’ own agent incidents are, in his view, mostly bad system administration. If OpenAI and Anthropic can’t watch their own agents, an ordinary IT team shouldn’t deploy them. Agentic loops exist because per-token prices are too low to fund the labs any other way. And the next wave, he predicts, will be people who reject Meta and install a “free-range, organic” agent built by the attackers themselves.
The core reporting checks out (Ars, InfoQ, Malwarebytes, 22 September). Meta patched the Mac app within about a day by removing the setting from production builds, and called it a local privilege escalation, not a remote exploit. Since the attack needs code already running on the Mac, some readers thought “zero-day” oversold it. Several of Eli’s side claims need correcting. The OpenAI account takeover went through OpenAI’s Discourse help forum, not Discord, and came in as a bug-bounty report. Anthropic’s evaluation agents broke into outside organisations starting in April 2026, disclosed on 30 July, not February to August. OpenAI’s cheapest current model costs $0.10 per million input tokens, not $0.20. Microsoft did warn that AI will mean bigger Patch Tuesdays, but put no 2027 date on it. All Things Open runs in October.
Connections
Links
- https://www.youtube.com/watch?v=RD7XUHQysTs
- https://www.infoq.com/news/2026/09/meta-muse-zeroday/
- https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor
- https://9to5mac.com/2026/09/22/security-bite-the-last-24-hours-at-meta-were-not-a-musing/
- https://venturebeat.com/security/meta-patched-muses-zero-day-but-security-teams-still-lack-visibility-into-what-the-agent-can-access
- https://www.techrepublic.com/article/news-amazon-blocks-meta-muse/
- https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
- https://www.axios.com/2026/07/30/anthropic-mythos-security-testing