Meta's new Muse AI assistant exposed its internal filesystem to users and carries a serious ClickFix vulnerability that can fully hijack the agent.
Days after launch, researchers found Muse would expose its filesystem to curious users, revealing internal details about how the chatbot operates. Separately, security researchers disclosed a 0-day vulnerability exploitable via a simple ClickFix attack that can completely hijack the assistant, which operates with extraordinary system privileges.
The dual disclosures come as Muse is drawing attention for stealing the AI spotlight from OpenAI and Anthropic with rapid feature rollouts, making the security gaps more consequential given the assistant's growing user base.
Shipping fast without hardening agent permissions is now a recurring failure mode across the industry, and Muse's privileged access makes this more than a cosmetic bug. For any company deploying agentic AI, this is the clearest case yet that security review needs to precede feature velocity, not follow it.
The daily signal, curated. Get it in your inbox.
Subscribe on LinkedIn →