Meta rushed its new Muse AI assistant to market with a zero-day vulnerability that gave any app on your Mac complete control over your digital life—and the flaw wasn't a bug, it was the inevitable result of a business model that demands access to everything you do.

Muse isn't a chatbot. It's an always-on agent that connects to your email, calendar, payment methods, shopping accounts, and smart home systems—then acts without you: booking travel, making purchases, filling out forms, and deciding what deserves your attention. Mark Zuckerberg claimed the product was "built from the ground up for privacy and security." A zero-day discovered by macOS security expert Patrick Wardle says otherwise.

Wardle found that any locally installed app or terminal command—regardless of its own macOS permissions—could access the authentication token controlling a user's entire Muse account. Attackers could have redirected Muse's transcription endpoint to their own server, intercepting everything. "We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told WIRED. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself." Wardle developed proof-of-concept attacks that wrote malicious files to disk and snapped pictures with no alert to the user.

The vulnerability existed because Muse requires users to authenticate it to every service and grant it sweeping operating system permissions—access to the mic, camera, location, and calendar. Apple spent years building those defenses to prevent exactly this kind of compromise. Muse dismantled them entirely. More than twelve hours after WIRED published its findings, Meta issued a hotfix.

Amazon started blocking Muse from its site on Sunday—a signal that even other tech giants don't trust what this thing does behind the curtain.

WIRED framed the story around the technical failure: a hyped product shipped with a catastrophic security hole. Just Security buried the zero-day entirely and framed Muse as a threat to human autonomy—a system that "decides what is worth doing" and quietly transfers agency from the person to a company with a long record of mishandling data. Both frames are correct. The security flaw and the autonomy problem share the same root: Meta built a machine that needs total access to function, and total access is exactly what makes it dangerous.

Muse is free for most users. Nothing running on expensive infrastructure is truly free. Meta's chief AI officer has already said the company is "exploring commerce opportunities" linked to Muse. Their own promotional material shows the model: Muse opens a travel itinerary, books a restaurant reservation at a newly opened spot, and the user simply agrees. Seamless. Frictionless. And completely opaque as to why that restaurant and not another.

Meta plans to integrate Muse into its AI glasses next. AR devices with sensors collect a more invasive class of data—what you looked at, how long you lingered, how your body responded—information you cannot review, undo, or opt out of because you don't know you're sharing it. An agent that knows when you're tired, stressed, or distracted, and stands to profit from the options it presents, is not an assistant. It's a harvester with a sales quota.

The hotfix patched the zero-day. It didn't patch the business model.