Meta CEO Mark Zuckerberg has prominently marketed the company’s new AI assistant, Muse, as being “built from the ground up for privacy and security.” However, the revelation of a critical zero-day vulnerability that allows locally run applications and terminal commands to seize complete control of the agent has cast significant doubt on those assurances. Compounding the security crisis, Amazon began blocking access to Muse from its platform on Sunday.
Launched a few weeks ago, the macOS-only application is designed to automate a wide array of personal tasks, including booking appointments, completing forms, managing customer service inquiries, generating images, and creating documents. The assistant integrates deeply with user accounts, connecting to WhatsApp, email, calendars, and social media platforms. In instances where a required tool is absent, Muse is capable of generating one dynamically. Notably, a Windows version of the app has not been released.
To function, Muse requires users to authenticate the assistant across multiple services and grant extensive permissions within the macOS environment. These privileges allow the app to write files directly to disk, access the microphone and camera, and monitor location and calendar data. Security experts note that these capabilities effectively negate years of Apple-developed safeguards intended to prevent installed applications or terminal commands from accessing such sensitive resources.
Mark’s privacy claims seem hollow now. Amazon blocking access suggests they see this as a serious risk. Hope they patch it soon.
This is exactly what I feared. An AI that can run terminal commands? That is a nightmare for security, not privacy.