SECURITY researcher Patrick Wardle has found a zero-day in Meta’s macOS AI assistant Muse that can allow any locally installed app or terminal command to take control of the user’s Muse account, regardless of its macOS permissions. Muse is designed to access services including WhatsApp, email, calendars and social media, while also receiving permissions to write files, use the camera and microphone, and monitor location.
Meta promotes the assistant as privacy- and security-focused, but its design permits local processes to alter undocumented settings, including the server endpoint used for cloud transcription.
An attacker who redirects that endpoint to a server they control can capture the token that authenticates the user’s Muse account. Wardle told Ars Technica that this lets an attacker use Muse’s own privileges to perform actions such as writing malicious files or taking photographs, sometimes without visible warning. He has developed proof-of-concept attacks and said a variation of the ClickFix technique can trigger the flaw through a simple terminal command.
In one scenario, an attacker’s proxy adds a malicious instruction to a voice prompt, potentially directing Muse to send an archive of WhatsApp messages; the stolen token can then provide continuing account control. The report does not identify a CVE or mention a fix. Meta did not answer emailed questions. Amazon separately began blocking Muse from shopping on its site, describing it as an unauthorised AI agent that violated its Conditions of Use and asking Meta to remove Amazon from the service.