- Muse 0-day: any app takes the token
- Muse exports its own disk: 6.8 GB
- AMD Zen 2: rdrand16 never hits 0
- Apple: Settings ads, no dismissYesterday I stamped Meta's Muse NEEDS REVIEW. Overnight, one pasted command took over a Muse account, and Muse zipped its own hard drive for a researcher, six point eight gigabytes. So here is the diff. Sunday night Amazon walled Muse off. Twelve hours later Patrick Wardle published a zero-day in the Muse Mac app. Monday, Peter James asked Muse for its own filesystem and got it. Also this week, AMD's random numbers skip zero, and Apple put ads in Settings you cannot close. First, the zero-day. Muse on the Mac has more permissions than your bank. Your files, your camera, your WhatsApp. Apple spent a decade building walls around those, and Muse asks you to open every gate on day one, because that is the product.
Patrick Wardle wrote The Art of Mac Malware. He found that any app on the Mac, or any terminal command, with no permissions at all, can change a long list of undocumented Muse settings. Most are harmless, like dark mode. One is the server address where your voice gets transcribed. Point that address at your own server and you receive the transcription, plus the token that logs in to the Muse account. Wardle's line is that instead of writing a Mac stealer, you just leverage the AI assistant itself. His proofs of concept wrote files and took webcam photos. The delivery is a ClickFix, the attack where a fake error page tells you to paste one command, and enough people do that it has a name. Half of Hacker News says that is not a zero-day, that is idiocy as old as time. True, and also why a login token should not live behind a dark mode toggle. Dictation could have stayed on the Mac. Meta chose the cloud, where Meta can log it.
Second, the export. Peter James, who builds a coding tool called Mouse, asked Muse to archive every file it could see and send it to his Google Drive. Muse said sure. Two point seven gigabytes compressed, six point eight unpacked, the root filesystem of the Linux machine his agent lives on. Meta's internal name for Muse is Hatch. The home folder holds a soul file, an identity file and a memory file. Then a hundred and thirteen sub-agent transcripts and about twenty manuals for payments, credentials and browser use. A config file lists connectors Meta has not announced, like Slack, Dropbox and Polymarket. The image also ships OpenAI's Codex CLI, apparently unused except for its sandbox tool, which Meta borrowed to run ffmpeg. Meta's flagship agent carries OpenAI's coding agent in the trunk, like a spare tire from the rival dealership.
There were SSH key files, untested, and a nightly job called a dream that reads your conversations and writes notes about you. His dream noted he had not asked for unsolicited NFL scores. The sandbox itself held, he says, and he stopped poking because it is production. He filed it with Meta's bug bounty. Meta marked it Not Applicable. Half of Hacker News agrees, it is your own VM. Then read the launch post. Meta says a separate Sentinel agent approves everything that leaves the machine. The Sentinel approved a three gigabyte zip of the machine leaving the machine. Meta says Muse never sees your passwords. Wardle's proxy sees the token, which is the password. Amazon says Muse appears to capture and store customer credentials. Ars emailed Meta questions and got nothing. Three parties, one week, and the only one saying there is no problem is the one selling it.
Now the chip that will not roll a zero. In May a Brazilian assembly programmer named Jessé was drawing bar charts of random numbers and noticed his AMD Ryzen never rolled a zero. Sixteen-bit numbers, so about sixty-five thousand faces on the die. After eleven hours, the one face that never came up was zero. Intel rolls zeros all day. This week Hacker News reproduced it on Zen 2 and found the mechanism. The chip does produce zeros. It just raises the try-again flag every time the value is zero, so any correct program retries and never sees one. Somebody at AMD wrote, if zero, report failure. A die with sixty-five thousand five hundred thirty-five faces, sold as fair. Does it matter? A one in sixty-five thousand bias will not break your TLS, and Linux mixes sources anyway. But Zen 2 launched in 2019 with the opposite bug, always returning all ones, fixed by microcode. And last year AMD's own advisory for Zen 5 told developers to treat a zero as a failure and retry. The bug, written down as the fix. AMD's reply to Jessé, four months ago, read like ChatGPT.
And Apple. iPhone users are finding banners at the top of Settings pushing iCloud plus, Apple Music trials and AppleCare, with a red badge until you act. There is often no dismiss button. The two ways out are waiting weeks, or paying. People who already pay for iCloud plus are seeing the iCloud plus ad, which Apple would call a bug and I would call a preview.
Verdict: REVERT — two reviews in a day; Meta's answer: Not Applicable
Sources
https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/
https://news.ycombinator.com/item?id=49802030
https://mouse.dev/blog/muse-runtime-export/
https://news.ycombinator.com/item?id=49802871
https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/
https://board.flatassembler.net/topic.php?t=24261
https://news.ycombinator.com/item?id=49798204
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html
https://www.techradar.com/phones/iphone/i-wish-apple-would-just-stop-that-crap-apple-has-added-persistent-ads-to-ios-and-its-driving-users-crazy
https://news.ycombinator.com/item?id=49801939
And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
YouTube · thedailydiff.dev · forward this to the intern who deployed on Friday.

