Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

A macOS zero-day in Meta’s new AI assistant Muse allows locally run apps or terminal commands to seize the authentication token and fully control a user’s agent by changing an undocumented transcription endpoint to an attacker-controlled server. Researcher Patrick Wardle demonstrated proof-of-concept attacks that use the flaw to perform actions like writing files and taking pictures without obvious user alerts, and Amazon has begun blocking Muse from making purchases on its site.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 3 hours agoUpdated about 3 hours ago0 views
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Why It Matters

Muse is designed to integrate with users’ accounts and device resources (email, WhatsApp, calendar, microphone, camera, files), so a vulnerability that hands an attacker a full authentication token gives broad access to sensitive data and device capabilities. The issue undercuts Meta’s public claims that Muse was built with strong privacy and security protections.

Key Facts

  • Vulnerability discovered by: Patrick Wardle (macOS security researcher)
  • Platform affected: Muse macOS app (no Windows version at launch)
  • Type of flaw: Local zero-day allowing apps/commands to read Muse auth token by changing undocumented settings
  • Attack vector: Changing transcription endpoint from Meta’s servers to an attacker-controlled server
  • Proof-of-concept capabilities: Writing malicious files to disk and taking pictures without obvious user indication

Meta released Muse as an agentive assistant that can book appointments, fill forms, make purchases, generate images and documents, and connect to services such as WhatsApp, email, calendars and social media. The macOS app requires broad device permissions — including file write access, microphone and camera use, and calendar access — and authenticates to third-party services on a user’s behalf.

Wardle reported a zero-day in Muse that lets any locally running application or terminal command change a set of undocumented settings used by the assistant. Among those settings is the address of the service that handles speech transcription. By rerouting transcription to an attacker-controlled endpoint, a local process can obtain the token that authenticates the Muse account and then operate the assistant with the account’s privileges.

Wardle said he built several proof-of-concept attacks that leverage the compromised agent rather than creating a traditional macOS stealer, demonstrating actions such as writing files to disk and capturing images, often without clear signs to the user. He also criticized design decisions — including routing dictation through Meta’s cloud rather than local on-device transcription and permitting any local app to alter undocumented settings — as making the exploit possible.

Meta published posts describing design choices for Muse’s privacy and security, but did not respond to emailed questions about the reported zero-day. Separately, roughly 12 hours before Wardle disclosed the vulnerability, Amazon began blocking Muse from making purchases on its site, saying Muse is an “unauthorized AI agent” in violation of its Conditions of Use and asking Meta to remove Amazon from the experience.

Keep Reading