Meta’s Muse has a serious 0-day

https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/

Comments

gavinraySep 22, 2026, 4:30 PM
The "zero day" is something they call a "ClickFix Attack"

Upon Googling "ClickFix":

  > "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"
I'm sorry, that's not a zero-day, that's idiocy that's as old as time.
bachittleSep 22, 2026, 7:31 PM
The exploit is a local zero day exploit, meaning the machine needs to already be compromised. For it to be a remote zero day exploit you need to do the ClickFix attack. The idea is that it lets you access much more machines and resources if the one machine with Muse is compromised. More info here: https://x.com/dps/status/2102248329111634067
failbufferSep 22, 2026, 4:38 PM
We filed a bug report but the original maintainer seems to have dropped offline. The community's had some success in correcting bugs with low-level hacking, but it's hard to make progress without the source code.
dspillettSep 22, 2026, 7:48 PM
> > It typically compromises devices by manipulating victims into copying and pasting malicious commands

> […] that's idiocy that's as old as time.

And constantly being reinvented: `curl -sL some.unverified.stuff.sh | bash`

bigfishrunningSep 22, 2026, 7:16 PM
Reminds me of playing Runescape back in the late 90s, you could double your money by just pressing alt-F4
analog31Sep 22, 2026, 7:21 PM
Well if nothing else, idiocy that's as old as time started on day zero.
theultdevSep 22, 2026, 5:06 PM
words don't seem to mean anything anymore.

clickbait headline should be changed, not a 0-day.

liroleroSep 22, 2026, 5:20 PM
[dead]
willtemperleySep 22, 2026, 3:06 PM
Who in their right mind would install a Meta AI with near admin privileges?
josefrescoSep 22, 2026, 4:07 PM
"Normies" aka the average user on Meta. They have no concept of what "admin privileges" means and don't really care. I still have a hard time convincing my clients to use secure passwords. I have clients who were phished for substantial amounts of money and STILL don't implement proper security measures.
sandeepkdSep 22, 2026, 3:57 PM
Almost everyone who is struggling with AI insecurity and is afraid of being left behind
shimmanSep 22, 2026, 4:07 PM
No, most workers don't really say this in surveys and polling. They tend to hate LLM tools because it makes their jobs worse, nothing about being left behind.

The only people pushing the "left behind" narrative is SV + SF + VC since their previous narratives have failed to persuade the public (thank fuck).

dgellowSep 22, 2026, 4:24 PM
I’m pretty sure you misread the comment you responded to
mattbrewsbytesSep 22, 2026, 6:31 PM
This is kinda the reason why the Meta stock might be pumping and Muse might leap ahead other AI solutions as far as market share goes. Quoted from Prof G Markets podcast: "meta has been molesting your privacy for 10 years".

It stands to reason their daily active users just don't care, they are already sharing so much on Meta's platforms it won't matter to them.

imageticSep 22, 2026, 3:24 PM
We all fear the true answer to that question.
apazzoliniSep 22, 2026, 4:40 PM
> Who in their right mind would install a Meta AI

I fixed it for ya

jsbisviewtifulSep 22, 2026, 3:42 PM
Normally I’m not one to blame the victims but, uh, yeah who in the world is dumb enough to trust Meta at this point?
dgellowSep 22, 2026, 4:24 PM
Billions of people
jsbisviewtifulSep 22, 2026, 5:12 PM
Sad, yet true
snapcasterSep 22, 2026, 3:33 PM
almost every normal person
john_strinlaiSep 22, 2026, 3:54 PM
most people don't know or care what "admin privileges" even means, or why they wouldn't want ai to have them
sick_of_slopSep 22, 2026, 3:42 PM
“They trust me, dumb fucks”.
alex1138Sep 22, 2026, 4:11 PM
And before this gets flagged or downvoted or "he was young" or "he was joking" or "he was making a point: he was saying 'I could be anyone', not that he can't be trusted" answer me what other tech people say this, ever, along with all the other charges ("I'm going to fuck them [the Winklevoss twins] in the ear", "You can be unethical and legal and that's how i live my life haha", hacking Crimson reporters, and that's just at Harvard, let alone when Facebook became available to the public
matroxmemoriesSep 22, 2026, 4:51 PM
Honestly, a lot of people start using this line of humor when their peers do. Add in that he was young, and this was before people’s private messages being released easily to the masses was common, Im not really surprised.
bigfishrunningSep 22, 2026, 7:23 PM
> people’s private messages being released easily to the masses was common, Im not really surprised.

He, personally, did a lot to enable this reality.

cindyllmSep 22, 2026, 9:09 PM
[dead]
alex1138Sep 22, 2026, 5:03 PM
[flagged]
yalokSep 22, 2026, 3:42 PM
> macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device

Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…

corvadSep 22, 2026, 6:53 PM
Click-bait title huh. This is not even close to a 0-day. I guess that word has lost all meaning to ArsTechnica huh.
TiredOfLifeSep 22, 2026, 7:06 PM
ars and the register have always been closer to the onion than journalism
sippingabonedrySep 22, 2026, 3:39 PM
Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.
NDlurkerSep 22, 2026, 5:53 PM
Why would they pay Muse? Muse the band doesn't have a monopoly on the word muse
dylan604Sep 22, 2026, 6:12 PM
because they had control of the handles used on Meta's apps. Why is that hard to understand. I was shocked they paid them instead of just taking it.
NDlurkerSep 23, 2026, 1:35 PM
I thought you were talking about trademarks, not user names
axusSep 22, 2026, 3:55 PM
Did the band end up getting money for that?
echelonSep 22, 2026, 4:07 PM
Presumably. They changed their handle on non-Meta social networks to match at around the same time as the Meta handle change.
ilSep 22, 2026, 4:19 PM
How is this a serious zero day if it requires local code execution to run?
chewsSep 22, 2026, 5:37 PM
I love that when you open a web inspection console on facebook, it says "Stop! This is a browser feature intended for developers. If someone told you to copy-paste something here to enable a Facebook feature or "hack" someone's account, it's a scam and will give them access to your Facebook account. See https://www.facebook.com/selfxss for more information."
dylan604Sep 22, 2026, 6:16 PM
I've used the devtools for years now, but for whatever reason, it never occurred to me to try and format the text like that. Too bad that that message is not clean as there were plenty of other things in the console so that I actually had to scroll around to find it. Had someone asked me to open the console and do something, I would not have seen the message.
tw600040Sep 22, 2026, 6:36 PM
People are giving Meta access to their emails, messages and calendars and other apps? Are they out of their mind or what am I missing?
nzoschkeSep 22, 2026, 7:05 PM
People are both lazy and curious. Meta is an attention grabbing juggernaut. Put the two together and plenty of people will experiment with giving Meta / Muse access to more of their digital lives.

It's scary to think how the hyperscalers will continue to get more and more access into everyones tools and lives under the guise of "AI assistant".

dmixSep 22, 2026, 6:48 PM
They also give them to Google in Gmail
tw600040Sep 22, 2026, 7:42 PM
Gmail is 1 part of the puzzle. A big part but still one part. But when you give something access to your email, calendar, iMessage, browser, passkeys of other apps, location it can autocomplete the missing parts and can pretty much complete the jigsaw.
dmixSep 22, 2026, 8:59 PM
I would never run Grok Bot or Muse with any sort of authentication.

I did try booking a flight with Muse and it worked surprisingly well. But I never used it after.

adamsb6Sep 22, 2026, 4:46 PM
Is 12 hours to deliver a local privilege escalation fix not a good response time?
peri-clSep 22, 2026, 3:19 PM
I'm confused what the vulnerability is. Does macOS have some specific function for protecting key material, that it's unexpected that if you execute user-privileged code locally, outside of a sandbox, it gets full read access?
voxic11Sep 22, 2026, 3:26 PM
Yeah macOS security is capability based rather than purely identity based. So if you don't pass the required entitlements to an application then it cannot do stuff like read from the system keychain even if its running as your user.
eworldliveSep 26, 2026, 9:44 PM
[flagged]
SoftTalkerSep 22, 2026, 3:31 PM
A zero day? Of course it does. It likely has many. Given the history of software, it's impossible to think it wouldn't.
tcdentSep 22, 2026, 3:59 PM
You would think a website dedicated to talking about software engineering would agree with this sentiment wholeheartedly.
dgellowSep 22, 2026, 4:28 PM
A zero day generally means a vulnerability and associated exploit have been identified and the vendor didn’t yet provide a patch. It doesn’t just mean “there is a vulnerability”. To say that every software has vulnerabilities is just not a useful comment
Caracas288Sep 22, 2026, 5:28 PM
The difference between

"We found aliens!"

And

"Aliens are out there!"

dpoloncsakSep 22, 2026, 7:49 PM
It's a zero day that has been released to the public with full exploit code.

You're missing the important part there.