Meta's Muse AI assistant ships with critical security flaw
macOS security researcher demonstrates zero-day vulnerability that grants attackers full control over the privileged AI agent.
Meta's newly launched Muse AI assistant contains a serious security vulnerability that allows any locally installed application or terminal command to completely hijack user accounts, according to macOS security researcher Patrick Wardle.
The flaw undermines Meta CEO Mark Zuckerberg's claims that Muse was "built from the ground up for privacy and security." The assistant, which launched several weeks ago, requires extensive permissions to book appointments, make purchases, and access users' WhatsApp, email, calendar, and social media accounts.
How the exploit works
The zero-day vulnerability stems from Muse's design choices around user dictation and transcription. While macOS provides secure, on-device transcription capabilities, Meta chose to process dictation in the cloud on its own servers.
Wardle discovered that any app or terminal command—regardless of its macOS permissions—can modify undocumented Muse settings, including the endpoint where transcription occurs. By redirecting this endpoint to an attacker-controlled server, malicious actors can intercept the authentication token that grants complete control over a victim's Muse account.
"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars Technica, which first reported the vulnerability. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself."
Wardle has developed proof-of-concept attacks that write malicious files to disk and capture photos, often without alerting even vigilant users.
Why it matters
AI assistants like Muse represent a new attack surface that concentrates extraordinary privileges in a single application. Unlike traditional malware that must painstakingly request individual permissions, compromising Muse grants attackers immediate access to everything users have already authorized—email, messaging, financial accounts, and device sensors. The vulnerability demonstrates that AI agent security remains immature even at major technology companies, raising questions about whether the industry is moving too quickly in deploying these powerful tools.
Simple attacks, serious consequences
The vulnerability can be exploited through variations of "ClickFix" attacks—social engineering techniques that trick users into running malicious commands. Wardle demonstrated that a simple terminal command can surreptitiously send prompts to Meta's endpoint and receive responses, all while the user remains unaware.
Once an attacker's server acts as a proxy between the user and Meta's legitimate endpoint, they can inject malicious commands into voice prompts. For example, an attacker could instruct Muse to send an archive of all WhatsApp messages to their server. The authentication token is automatically transmitted to the malicious server, granting permanent account control.
Design decisions under scrutiny
Wardle, founder of the Objective-See Foundation and author of "The Art of Mac Malware" book series, criticized Meta's security approach. He pointed to two critical design flaws: choosing cloud-based transcription over macOS's secure on-device option, and allowing any application to control sensitive endpoint settings.
"At the very least, they should be thinking about security from the very start, and they are just not," Wardle said. He plans to discuss the vulnerability in detail at the Objective by the Sea security conference in November.
Meta did not respond to questions about the vulnerability. Amazon began blocking Muse from its shopping site roughly 12 hours before Wardle's disclosure, citing violations of its terms of service and calling Muse an "unauthorized AI agent."
The security flaw was first reported by Ars Technica.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
