Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
Meta's Muse agent shipped with a zero-day that gave attackers full machine access. The fix is out, but the incident exposes a critical gap: AI agents executing commands with fewer guardrails than traditional software.

Why it matters
A zero-day in a deployed AI agent demonstrates the security surface area that autonomy introduces — and why agent reliability and exploit detection are now table-stakes for production deployments.
The key facts
5 to knowMeta Muse AI assistant shipped with zero-day vulnerability
Vulnerability allowed attackers to execute arbitrary commands on victim's Mac
Meta issued a fix after disclosure
Incident highlights agent security and execution risks
Date: September 23, 2026
The story so far
Earlier coverage of this storyline
- Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-dayArs Technica
- This story
Go to the source
Wired AIwired.com
Publisher excerpt: Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.