Zero-day flaw exposes Meta's Muse AI assistant on macOS
A newly discovered zero-day vulnerability in Meta's Muse AI assistant for macOS allows local applications to hijack user accounts and abuse the tool's extensive system privileges.

Security researcher Patrick Wardle has uncovered a critical zero-day vulnerability in Muse, Meta's recently released AI assistant for macOS. The security flaw allows any locally running application or terminal command to bypass standard operating system protections and seize complete control of the assistant. This vulnerability compromises the extensive system permissions users grant to Muse, which include accessing microphones, cameras, location data, and writing files directly to disk.
The security flaw stems from how Meta developers designed Muse's configuration settings. Any local process, regardless of its privilege level, can modify undocumented settings within the application. Most notably, an attacker can change the server endpoint used for voice transcription from Meta's official servers to a malicious proxy. Once redirected, the attacker can capture the authentication token that validates the user's account, granting them permanent access to the victim's Muse integration with services like WhatsApp, email, and calendars.
According to Wardle, who plans to present his findings at the Objective by the Sea conference in November, this design flaw makes traditional malware development unnecessary. Attackers can simply "leverage the AI assistant itself" to execute malicious commands, such as snapping photos or writing dangerous files, without alerting the user. Wardle noted that Meta could have avoided this issue by utilizing macOS's built-in, on-device transcription capabilities rather than routing dictation through the cloud.
The disclosure of the zero-day follows a decision by Amazon to block Muse from its platform. Roughly 12 hours before Wardle revealed the flaw, Amazon began preventing Muse from making purchases, citing violations of its terms of service and calling it an unauthorized agent. For AI developers and security practitioners, the vulnerability highlights the severe risks of building highly privileged agentic tools without rigorous local security boundaries, demonstrating how easily a compromised device can turn a trusted assistant into a powerful vector for exploitation.
This is our own summary of reporting by Ars Technica AI



