Meta AI assistant weakness puts connected accounts and devices at risk
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 22nd, 2026.
A reported weakness in Meta’s Muse assistant could allow locally running applications or terminal commands to take control of a user’s Muse account. That matters because Muse can access WhatsApp, email, calendars, files, location, the microphone, and camera.
The reported attack changes the service Muse uses for transcription and captures the account token sent there. An AI assistant’s broad permissions can turn one weak control into access across many trusted services. The attack reportedly works even when the initiating local process lacks the macOS permissions that Muse holds. Meta didn’t answer questions before publication, and the report doesn’t identify a fix.
For organizations, the main concern is permission concentration. A single weak control in a highly connected assistant can expose many trusted services at once. Leaders should apply a higher approval bar to agentic tools because their authority can exceed that of ordinary applications. Defenders should restrict deployment, minimize connected accounts, and monitor changes to service settings and endpoints. Until Meta provides a verified fix, restrict Muse deployment and revoke unnecessary permissions. The larger lesson is that delegated AI authority can amplify a local weakness into a cross-account compromise.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.