Meta's Muse AI assistant hit by serious 0-day vulnerability
Original: Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Why This Matters
Agentic AI assistants with OS-level access create a single high-value target that collapses multiple security boundaries at once.
Security researcher Patrick Wardle disclosed a zero-day in Meta's Muse AI assistant for macOS. Any locally installed app or terminal command can steal the user's authentication token by redirecting the transcription endpoint, granting full account control. Amazon has blocked Muse from its site.
Meta's Muse, an agentic AI assistant launched weeks ago, can book appointments, fill forms, make purchases, generate images, and connect to WhatsApp, email, calendars, and social media. Because it runs on macOS, users must grant it sweeping OS-level permissions — microphone, camera, file writes, location — bypassing the very sandboxing protections Apple has spent years building.
Now those broad privileges are a liability. macOS security researcher Patrick Wardle found that any locally installed app or terminal command, regardless of its own permissions level, can modify a long list of undocumented Muse settings. One setting controls where audio transcription is sent. Attackers can silently redirect it to their own server, capturing the authentication token that grants complete control over the Muse account.
"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars Technica. "Instead of writing very comprehensive Mac malware, we can just leverage the AI assistant itself." He has built multiple proof-of-concept exploits that write malicious files and capture photos, often with no visible indicator to the user.
This lands awkwardly for Meta: the company published two blog posts in two weeks detailing how Muse was "built from the ground up for privacy and security." Meta did not respond to Ars's questions. Separately, Amazon has begun blocking Muse from its site. No patch or timeline has been announced.