Tuesday, 29 September 2026 Login

Code Without Boundaries

BREAKING
Edge Computing

Meta fixes Muse AI flaw but leaves enterprise security blind

Chain-locked book, phone, and laptop symbolizing digital and intellectual security.
Chain-locked book, phone, and laptop symbolizing digital and intellectual security. Photo: Pixabay/Pexels

Meta addressed a critical zero-day flaw in its Muse AI assistant that permitted malware operating under a user’s credentials to seize authentication tokens without needing raised privileges. Security expert Patrick Wardle revealed the vulnerability on Monday, showing how an attacker could reroute Muse’s transcription endpoint to capture the token controlling the agent. In a live demonstration, Wardle used a compromised session to locate an iPhone in Barcelona and trigger a Bluetooth Low Energy scan.

Since its launch on September 8, Muse has achieved over 2.5 million downloads in just 13 days, according to app tracking data. The tool can automate tasks such as composing emails, booking travel, filling forms, and making purchases on behalf of users, along with integrating external services through custom connectors. While Meta’s security documentation outlines a dedicated virtual machine for each user, separating credentials from the agent’s operations, Wardle’s exploit targeted the Mac client, released nine days after the initial launch, bypassing cloud-based safeguards.

The company resolved the issue within 24 hours by removing an undocumented configuration from production versions. Meta classified the problem as a local privilege escalation rather than a remote exploit. Wardle confirmed the patch on Tuesday but warned that attackers could still manipulate users into executing commands, similar to ClickFix tactics, to replicate the same outcome.

The incident also highlighted a significant enterprise security shortfall: Muse operates with the same permissions as its users, yet organizations lack tools to monitor how the agent interacts with connected services. Meta’s consumer audit logs track user actions, but tests by VentureBeat found no equivalent enterprise solutions, no SIEM integration, IT admin console, or data loss prevention (DLP) mechanisms. The company did not provide a response to inquiries.

Meta’s Sentinel system manages OAuth tokens by exchanging them at the network boundary, preventing the agent from directly storing credentials. However, API keys supplied by users do not trigger OAuth oversight, leaving security teams unable to detect unauthorized access. Without visibility into API-key usage, connector activity, or service-level logs, companies may fail to identify misuse, even with existing OAuth protections in place.

The company announced plans to deploy a Confidential VM in late 2026 to further limit its own access to user data. Until then, the absence of enterprise-grade audit tools and the agent’s broad permissions expand potential attack points. Employees deploying Muse could inadvertently expose corporate systems to risks that traditional security tools may not recognize.

Tags:

Leave a Reply

Your email address will not be published. Required fields are marked *