Safety & Security

Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover

A zero-day in Meta's Muse let any local app or terminal command hijack a user's account by redirecting transcription to an attacker-controlled server. Meta patched it only after disclosure.

Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
Meta’s Muse AI Assistant Rolled Out With a Serious Security FlawAI-generated
By Sophie Lindqvist5 min read

Updated

Why it matters

  • A zero-day in Meta's Muse let any local app or terminal command change the transcription endpoint to an attacker-controlled server and steal the account token granting full control.
  • macOS security researcher Patrick Wardle, creator of the Objective-See Foundation, developed proof-of-concept attacks that wrote malicious files to disk and took pictures with no user indication.
  • Amazon began blocking Muse from its site, calling it an "unauthorized AI agent [that] violates Amazon's Conditions of Use," and asked Meta to remove Amazon from the experience.

A zero-day vulnerability in Meta's Muse AI assistant let any locally installed app or terminal command seize complete control of a user's Muse account, directly undercutting Mark Zuckerberg's claim that the assistant is "built from the ground up for privacy and security."

Meta shipped a hotfix only after disclosure, more than 12 hours after the findings went public. The flaw is the second major setback for the assistant in a week: on Sunday, Amazon began blocking Muse from its site, telling users the assistant was an "unauthorized AI agent [that] violates Amazon's Conditions of Use."

Patrick Wardle, the macOS security expert who discovered the vulnerability, described the impact bluntly. "We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars ahead of the hotfix. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself."

Wardle, creator of the Objective-See Foundation and author of The Art of Mac Malware book series, has built several proof-of-concept attacks. They write malicious files to disk and take pictures with the camera, in many cases without any indication to even an alert user.

How the attack worked

Muse, launched a few weeks ago as a macOS-only app (there is no Windows version), "books appointments, fills out forms, and handles customer service," "proactively takes tasks off your plate," and can "make purchases, generate images, create documents, and connect with your favorite apps and services." It connects to a user's WhatsApp, email, calendar, and social media accounts, and creates new tools on the fly when a task requires one.

That reach demands access to operating system-restricted resources: writing files to disk, using the microphone and camera, monitoring location and calendars. Apple has spent years building macOS defenses to keep installed apps and terminal commands away from these resources. Muse bypassed that architecture entirely.

Meta designed Muse so that any locally installed app or executed code, regardless of its macOS permissions, could change a long list of undocumented settings. Most were harmless, such as toggling dark mode. One was not: it allowed processes to change the endpoint where voice transcription occurs, normally a Meta-operated server. An attacker could redirect that endpoint to a server of their own — and receive the token that authenticates complete control over the Muse account.

Wardle outlined a concrete attack chain. An attacker's server acts as a proxy between the Muse user and Meta's endpoint. When the user speaks a prompt, the attacker's server injects an additional malicious command, such as sending an archive of all WhatsApp messages to the attacker. The token travels to the malicious server automatically, giving the attacker permanent control of the account.

Design choices under scrutiny

Wardle said two Meta decisions made the exploit possible. First, Muse handles dictation in the cloud, where Meta can log it. macOS has long offered on-device dictation and transcription that would have made the attack impossible. Meta has yet to explain why it chose the cloud-based option. Second, allowing any app to control all of the undocumented settings — including the endpoint where sensitive user speech is processed — placed a dangerous capability in unprivileged hands.

"To me, the bar is infinitely higher in terms of the security of these apps," Wardle said. "They don't have to be perfect, but when you take a look at Muse, it's like they didn't, in my opinion, think about security, which is really worrisome. At the very least, they should be thinking about security from the very start, and they are just not."

The stakes extend beyond one product. Meta published two posts in as many weeks defending the security design of an assistant with extraordinary access to user data. Those posts followed revelations that internal testing of models from Anthropic and Google had breached third-party networks the engineers never intended to target — actions that, in traditional human-only hacking, could likely bring criminal charges. The episode feeds growing calls to slow AI agent development.

Not just a local compromise

Meta's statement after the hotfix called the zero-day "not a remote exploit." Wardle's findings challenge that framing. He found that a simple variation of a ClickFix attack — a social engineering technique that has become remarkably effective at tricking people into infecting their own devices — was all an attacker needed to take over a Muse account. He demonstrated a terminal command that surreptitiously sent a prompt to Meta's endpoint; Muse incorrectly responded that such an action wasn't possible.

Amazon, for its part, framed its blocking of Muse as a matter of consent. "We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate," the company said in an emailed statement, adding that it had "requested that Meta remove Amazon from the experience."

Wardle plans to present the vulnerability and other AI assistant threats in more detail at the Objective by the Sea security conference in November. As Meta's own claims meet evidence to the contrary, the central question now hanging over Muse is the one Ars posed: like most such AI agents, Muse can't yet be trusted — and it is not clear when, or if, it ever can be.

Original: x.com

Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Staff writer covering marketplaces and e-commerce at AI In Context.

115 articles

Related articles

  1. Meta Rushed to Patch a Zero-Day Bug in Its Muse AI Agent
  2. Zero-Day in Meta's Muse AI Assistant Undoes macOS Defenses
  3. Developers Say Meta's Muse Hands Over Its Entire Filesystem on Request
  4. Meta Says Muse's Exposed Filesystem Is Intended Behavior

Next article »