Meta launched Muse, an AI-driven personal assistant for macOS, only weeks ago. The software can schedule meetings, fill forms, handle customer service, make purchases, generate images, create documents, and interact with popular apps such as WhatsApp, email, calendars, and social media. Because the assistant performs these actions on the user’s behalf, it requires authentication to each linked service and extensive macOS permissions, including file-system writes, microphone, camera, location, and calendar access.
The zero-day flaw permits any locally installed application or command-line instruction, regardless of its granted macOS privileges, to modify a hidden list of settings within Muse. While most of these toggles appear harmless,such as dark-mode control,one undocumented option lets a process redirect the transcription endpoint away from Meta’s servers. By pointing this endpoint to an attacker-controlled server, the malicious party can capture the authentication token that grants unrestricted control over the user’s Muse account.
macOS security researcher Patrick Wardle identified the vulnerability and demonstrated several proof-of-concept attacks. He showed that the compromised assistant could write malicious files, capture webcam images, and exfiltrate data without triggering any user alerts. Wardle told Ars Technica that the exploit allows “manipulate the agent and leverage its privileges to do whatever we want,” effectively turning Muse into a conduit for malware rather than requiring a separate, complex stealer.
Meta responded to the disclosure by issuing a hotfix roughly twelve hours after the vulnerability was made public. The company’s brief statement acknowledged the issue but omitted details about the ease of executing ClickFix-style attacks, a technique Wardle highlighted as sufficient to hijack a Muse account. This rapid patch follows two recent Meta blog posts that attempted to justify the assistant’s extensive data access by emphasizing security and privacy safeguards.
Wardle criticized two key design choices that enabled the exploit. First, Muse routes voice transcription to Meta-controlled cloud servers, ignoring macOS’s built-in on-device dictation framework that would keep audio data local and insulated from tampering. Second, the assistant exposes a broad set of undocumented preferences to any cooperating app, allowing unrestricted modification of critical parameters such as the transcription endpoint. Together, these decisions raise concerns about the rigor of security testing for AI-driven assistants.
Exploiting the altered endpoint can be as simple as inserting a malicious prompt via a ClickFix-style terminal command, causing Muse to forward the user’s voice request to an attacker-run server that can issue further commands, such as exporting all WhatsApp messages. Once the token is delivered to the malicious server, the attacker retains permanent control over the assistant. Wardle plans to present additional details on this and broader AI-assistant threats at the Objective by the Sea security conference in November.