Meta's Muse AI assistant contained a critical 0-day vulnerability allowing local applications to steal user authentication tokens and gain full control of accounts. Researcher Patrick Wardle demonstrated proof-of-concept attacks including malicious file creation and photo capture; Meta released a hotfix within 12 hours. Amazon has begun blocking Muse's shopping functionality citing unauthorized AI agent status.