Meta recently introduced its new AI assistant, Muse, but the rollout has been marred by the discovery of a significant zero-day vulnerability. The security flaw, found in the macOS application, would have allowed any locally running app or terminal command to gain complete control over a user’s Muse account, raising serious doubts about the company’s claims that the assistant was “built from the ground up for privacy and security.”
The zero-day vulnerability specifically allowed malicious processes to access the authentication token required to log into Muse. Patrick Wardle, a macOS security expert who identified the flaw, stated that this design oversight meant attackers did not need to create complex malware. Instead, they could simply leverage the AI assistant itself to perform actions on the victim’s device.
“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle explained. He demonstrated proof-of-concept attacks that included writing malicious files to disk and taking photos, often without the user’s knowledge.
Meta had previously emphasized Muse’s extensive capabilities, noting that the assistant can book appointments, fill out forms, handle customer service, make purchases, and create documents. To function, users must grant Muse access to their WhatsApp, email, calendar, and social media accounts, as well as permissions for microphone, camera, and location data. However, the assistant undermines many of macOS’s default security protections by allowing these broad accesses.
Wardle pointed out that Meta made several design decisions that facilitated the exploit. One critical choice was requiring Muse dictation to occur in the cloud rather than locally on the device, which is a standard secure practice on macOS. Another involved an undocumented setting that allowed any local process to change the endpoint where transcription occurs. By redirecting this endpoint to a server controlled by an attacker, the hacker could intercept the authentication token.
More than 12 hours after the vulnerability was reported, Meta announced it had released a hotfix to patch the zero-day. Despite this response, the incident has drawn criticism, especially as Amazon began blocking Muse from its site shortly after the flaw became public. The situation comes amid broader industry concerns about AI safety, with recent reports of security breaches involving models from Anthropic and Google.
Interesting that Amazon blocked Muse. This could be the beginning of a wider industry rejection of poorly audited AI assistants.
Cloud-only dictation? That is a glaring security oversight for a macOS app. This screams ‘move fast, break things’ gone wrong.
I thought I was safe with my new assistant! Guess I’ll uninstall immediately until they fix this mess properly.
Twelve hours is an eternity when you’re selling privacy. Meta really needs to tighten its red lines before this expands.