Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Meta's new AI agent has a critical 0-day. A simple ClickFix attack can hijack it entirely.

Why it matters
Agent security vulnerability in production deployment. A 0-day in a privileged agent used at scale raises urgent questions about agent reliability and threat surface in enterprise deployments.
The key facts
5 to knowMeta agent 'Muse' has critical 0-day vulnerability
ClickFix attack method can completely hijack the agent
Agent described as 'extraordinarily privileged' — high system access
Published by Ars Technica (credible security outlet)
September 2026 publication date
Go to the source
Ars Technicaarstechnica.com
Publisher excerpt: A simple ClickFix attack is only one way to completely hijack the new agent.

