Meta's Muse AI Assistant Had Zero-Day Flaw Exposing User Accounts
A security researcher discovered that any local app could hijack the authentication token for Meta's new AI agent, which requires extensive system permissions to function.

Meta's Muse AI Assistant Had Zero-Day Flaw Exposing User Accounts
Meta's recently launched AI assistant Muse contained a zero-day vulnerability that allowed any locally installed application or terminal command to gain complete control over user accounts, according to macOS security researcher Patrick Wardle. The flaw undermined Apple's operating system protections and contradicted Meta CEO Mark Zuckerberg's claims that Muse was "built from the ground up for privacy and security."
Why it matters
AI assistants require unprecedented access to user data and system resources to function—email, calendars, financial accounts, cameras, and microphones. This vulnerability demonstrates how a single design flaw can expose all of those resources at once, creating a single point of catastrophic failure. For enterprises evaluating AI agents, the incident highlights that security claims from even major vendors require independent verification.
How the vulnerability worked
Muse allows users to book appointments, make purchases, generate documents, and connect with services including WhatsApp, email, and social media. To enable these capabilities, users must grant the macOS application extensive permissions that Apple has spent years restricting by default.
Wardle, founder of the Objective-See Foundation and former NASA and NSA employee, discovered that Muse allowed any locally installed app to modify undocumented settings without requiring macOS permissions. While most settings controlled innocuous features like dark mode, one setting allowed processes to change the endpoint where voice transcription occurs—normally a Meta-operated server.
By redirecting transcription to an attacker-controlled server, malicious actors could intercept the authentication token that provides full access to a user's Muse account. "We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars Technica, which first reported the findings. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself."
Wardle developed proof-of-concept attacks that could write malicious files to disk and capture photos without alerting users. He noted that a simple ClickFix attack—a social engineering technique that tricks users into running terminal commands—could trigger the exploit remotely.
Design decisions under scrutiny
Wardle identified two critical design flaws. First, Meta chose to process dictation in the cloud rather than using macOS's built-in on-device transcription, which would have prevented the attack entirely. Second, Meta allowed any app to control all undocumented settings, including the sensitive transcription endpoint.
"At the very least, they should be thinking about security from the very start, and they are just not," Wardle said.
Meta released a hotfix more than 12 hours after Ars Technica published its report. The company's statement characterized the vulnerability as "not a remote exploit," though it did not address how ClickFix attacks could enable remote exploitation or explain why it chose cloud-based transcription over Apple's on-device alternative.
Amazon blocks Muse
Roughly 12 hours before the vulnerability disclosure, Amazon began blocking Muse from its platform, calling it an "unauthorized AI agent" that violates the company's terms of service. Amazon stated that third-party applications making purchases on behalf of customers should "operate openly and respect service provider decisions about whether or not to participate."
Wardle plans to discuss the vulnerability and other AI assistant security threats at the Objective by the Sea conference in November. Details were first reported by Ars Technica.
This is an original analysis by the Omega editorial team. Source reporting: WIRED.
Want systems like this working for your business?
Book a Call
