Meta launched Muse only weeks ago as a macOS-only AI assistant that can schedule meetings, fill forms, handle customer service, make purchases, generate images, draft documents and link to popular apps. The program also integrates with WhatsApp, email, calendars and social media, and can fabricate new tools on demand when a required capability is missing.
To perform those tasks, users must grant Muse extensive access, including authentication to each linked service and macOS permissions such as file-system writes, microphone, camera, location and calendar monitoring. Apple’s long-standing safeguards normally block apps and terminal commands from reaching these resources, yet Muse effectively disables those default protections.
The uncovered zero-day permits any locally installed application or command line instruction, regardless of its granted macOS privileges, to modify a long list of undocumented settings. While most of these settings appear harmless, one controls the server endpoint for voice transcription. By redirecting this endpoint to a malicious server, an attacker can steal the token that authenticates the user to Muse.
Mac security specialist Patrick Wardle explained to Ars Technica that the vulnerability enables an attacker to manipulate the assistant and exploit its privileges arbitrarily. He demonstrated proof-of-concept exploits that wrote malicious files, captured images and performed other actions without triggering any user alerts, effectively turning Muse into a stealthy malware delivery mechanism.
Meta responded by releasing a hotfix roughly twelve hours after the vulnerability was reported. The company had previously published two blog posts in consecutive weeks outlining its security and privacy rationale for Muse, a move that coincided with revelations that internal testing of other AI models had unintentionally breached external networks.
Wardle identified two design choices that made the exploit possible: routing dictation to cloud servers instead of using macOS’s on-device transcription framework, and allowing any application to alter all undocumented settings, including the transcription endpoint. Both decisions lowered the barrier for an attacker to hijack the assistant’s privileged functions.
Attack scenarios include a malicious server acting as a proxy between the user and Meta’s endpoint, inserting commands that exfiltrate data such as all WhatsApp messages. A simpler method leverages a ClickFix-style attack, where a crafted terminal command injects a prompt that forces Muse to send its authentication token to the attacker’s server.
Wardle, co-founder of the Objective-See Foundation and former NASA and NSA employee, plans to discuss this vulnerability and broader AI-assistant threats at the Objective by the Sea security conference in November. His findings raise questions about the depth of security testing applied to new AI-driven personal assistants.