7 Sources
[1]
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is "built from the ground up for privacy and security." A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises
[2]
Meta patches Muse exploit that let attackers control the AI agent
Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code
[3]
Meta Muse AI app flaw lets local malware redirect dictation traffic
Meta made much of the security of its AI assistant app Muse at launch earlier this month, calling out the app's reliance on Muse Secure VM. "Each person stays in control of their Muse and decides how much access it gets," the ad biz declared, echoing prior expansive claims about the privacy of its
[4]
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the
[5]
Security Bite: The last 24 hours at Meta were "not-a-musing"
9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated
[6]
Meta Muse already has a majorly worrying zero-day security issue
The company has been informed, but is yet to comment, or issue a patch * Researcher Patrick Wardle finds zero‑day in Meta's new Muse AI assistant, * Dubbed not‑a‑mused, the exploit requires local compromise, voice dictation, and app integrations; attackers can hijack tokens and exfiltrate data *
[7]
Meta's Muse AI agent is a big hit, and it just had a big security alarm go off, too
Muse can shop, handle emails, book appointments, and take care of everyday tasks for you. But that convenience requires considerable access, which makes a newly disclosed vulnerability particularly concerning. Meta's Muse is off to a strong start. The company's new personal AI agent has already
Share
Copy Link
Meta's newly launched Muse AI assistant faced a major security crisis when researcher Patrick Wardle exposed a zero-day vulnerability in its macOS app. The flaw allowed any locally installed app to redirect dictation traffic and gain complete control over user accounts, contradicting Meta's claims of building the assistant with security as a priority. Meta issued a patch within hours of disclosure.
Meta's AI assistant Muse, launched earlier this month with bold claims of being "built from the ground up for privacy and security," has been exposed to contain a serious zero-day vulnerability
1
. Security researcher Patrick Wardle discovered the flaw in the macOS AI agent, which allows any locally installed app or terminal command to gain complete control over a user's Muse account3
. The vulnerability directly contradicts Meta's extensive security assurances and raises questions about the company's development priorities as it races to compete with rival AI providers.
Source: Digital Trends
The zero-day vulnerability exploits an undocumented setting called endo_voyager_dictation_endpoint that controls where Muse sends dictation traffic
4
. Wardle demonstrated that any app or terminal command running locally on a Mac can modify this setting without requiring special macOS permissions, redirecting transcription from Meta's servers to an attacker-controlled endpoint1
. Once redirected, attackers gain access to authentication tokens that provide complete control over the Muse account. "We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself," Wardle explained2
.Wardle developed several proof-of-concept attacks showcasing the vulnerability's severity, including writing malicious files to disk and taking pictures using the device camera, often without alerting users
1
. The attack extends beyond the compromised Mac, as stolen session tokens can control Muse accounts across multiple devices. In testing, Wardle directed the Muse app on his iPhone to report exact location, run Bluetooth scans of nearby devices, and list available smart-home commands4
. The researcher named his proof-of-concept "not-a-mused," highlighting the irony of Meta's security claims3
.
Source: The Verge
The vulnerability stems from several questionable design decisions by Meta developers. First, Muse processes dictation in the cloud rather than using Apple's on-device dictation API, which would have prevented this attack entirely
1
. Second, Meta allowed any app to control all undocumented settings without proper access controls2
. Wardle suggested Meta's choice to avoid Apple's local dictation system stems from wanting access to user data: "I think some of their greediness for user data kind of opens the door, makes a bigger attack surface"3
.While the vulnerability requires local access rather than remote exploitation, security experts emphasize this represents a serious privilege escalation issue
3
. Apple has invested years developing its Transparency, Consent, and Control (TCC) framework to prevent apps from accessing sensitive resources without explicit permission. Muse effectively bypasses these protections by requesting broad access upfront. Wardle explained the concern: "Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments"3
. Local malware that would normally be restricted by macOS security can now leverage Muse's extensive permissions to access user data, files, and connected services.Related Stories
Meta released a hotfix within hours of the Ars Technica report publication
2
. David Singleton of Meta Superintelligence Labs downplayed the severity, stating on X that "this was a local privilege escalation attack, not a remote exploit" and that "the practical risk to users of the Muse Mac app was therefore quite low"2
. However, security experts remain concerned about Meta's development approach. Wardle questioned whether Meta is applying its AI capabilities to secure its own products: "You know these AI companies have really great AI models for finding bugs. Are they not running them against [their own apps]? Is the priority not the security of their own apps?"3
.Adding to Meta's challenges, Amazon began blocking Muse from its e-commerce platform approximately 12 hours before Wardle disclosed the zero-day vulnerability
1
. Users attempting to shop via Muse received messages stating the AI assistant was an "unauthorized AI agent [that] violates Amazon's Conditions of Use"1
. Amazon claims Meta never obtained permission to integrate Muse with its platform, creating additional friction for the newly launched assistant.The Muse vulnerability highlights systemic security challenges facing AI assistants that require extensive system access to function effectively. Wardle warned that AI apps are becoming "potentially a single point of failure that breaks operating system security controls"
3
. Endpoint detection and response software struggles to distinguish between legitimate user commands, AI agent actions, and attacker activity when agents hold broad permissions3
. "At the end of the day, these AI companies, they're racing for what's next. User privacy and security, those aren't priorities," Wardle concluded3
. Despite the security setback, Muse's mobile app reportedly outpaced ChatGPT's 12-day US and Canada debut downloads during its first 12 days, with Meta stock climbing 11 percent following the launch2
. Watch for increased scrutiny of AI assistant security practices and potential regulatory responses as these powerful tools gain mainstream adoption.
Source: The Register
Summarized by
Navi
[4]
08 Sept 2026•Technology

29 May 2026•Technology

16 Jul 2025•Technology

1
Technology

2
Science and Research

3
Technology
