MAC security researcher Patrick Wardle has found a zero-day in Meta’s Muse AI assistant that could allow an attacker to turn it into a powerful backdoor. According to Malwarebytes, Muse’s locally running macOS application has an undocumented configuration setting controlling the server used for dictation transcription.
A local application or terminal command can change this setting to an attacker-controlled server, allowing the attacker to capture voice prompts and obtain the authentication token for the victim’s Muse account.
Muse is designed to perform tasks including appointments, form completion, customer-service interactions, purchases and document creation. It can also connect to WhatsApp, email, calendars and social platforms, and may receive macOS permissions to access files, the microphone, camera, location and calendars. A compromised, authenticated agent could therefore provide access to several services and permissions through one interface.
However, the issue is not remote code execution: an attacker must first run code on the Mac, perhaps through malware, a malicious application or social engineering. The article does not report confirmed exploitation.
Wardle’s advice is not to install Muse. Users of AI agents should avoid granting broad access unnecessarily, review and remove unused connections, and watch for unexpected permission requests, reauthentication prompts, file sharing or actions they did not initiate. The article also advises keeping software updated, using current anti-malware protection and not running commands suggested by untrusted websites or unsolicited messages.