Meta's AI assistant Muse has a serious zero-day vulnerability, Ars Technica reported on 21 September — a disclosure that puts the spotlight less on the bug itself than on where the bug lives.

Muse, as Ars Technica frames it, is an extraordinarily privileged assistant. It is wired into the places in Meta's products where messages, accounts and connected services meet, which is exactly where an attacker wants to be. An assistant that can read context, act on a user's behalf and move between apps is useful for the same reason it is dangerous: the permissions that make it helpful are the permissions that make a single defect consequential. The blast radius of an assistant flaw is measured in accounts, not in windows.

This arrives on the back of a month of uncomfortable questions about Muse's reach. On 19 September, the assistant was already drawing privacy alarms after apparently accessing Mac notifications without explicit permission. A 0-day lands differently on software that has just been shown to be sitting very close to the user's personal data.

Zero-days in major platforms are routine. Zero-days in assistants are a newer class of problem. In two years the industry has wired chat interfaces into calendars, inboxes, browsers and code repositories through tool calls and 'agents', usually with broad, long-lived authorisations. The resulting attack surface is not the model or the app binary alone: it is the whole chain of credentials, extensions and memory stores around it. When a flaw lands in that chain, the useful question is not 'which app is affected' but 'what can this thing already do on my behalf, and without asking me again'.

What is not yet public matters as much as what is: the mechanics of the flaw, how it is triggered, whether a fix has shipped, and how a user would know if they were affected. Ars Technica's report is the place to check for those specifics, and any Meta advisory should be the source of truth for anyone running Muse.

For users, the practical response is the discipline assistants have always demanded and rarely get: keep the app updated, review which third-party services the assistant is authorised to touch, remove integrations you no longer use, and treat any assistant with account-level reach as a high-value target rather than a convenience. For the platforms, the open question is whether the assistant's authority gets scoped to the task at hand — or keeps expanding until the first serious incident forces the question.