Meta Muse AI Assistant Hit by Zero-Day Vulnerability Allowing Complete Account Takeover

7 Sources

Share

Meta's newly launched Muse AI assistant faced a major security crisis when researcher Patrick Wardle exposed a zero-day vulnerability in its macOS app. The flaw allowed any locally installed app to redirect dictation traffic and gain complete control over user accounts, contradicting Meta's claims of building the assistant with security as a priority. Meta issued a patch within hours of disclosure.

Meta Muse Security Claims Contradicted by Zero-Day Discovery

Meta's AI assistant Muse, launched earlier this month with bold claims of being "built from the ground up for privacy and security," has been exposed to contain a serious zero-day vulnerability

1

. Security researcher Patrick Wardle discovered the flaw in the macOS AI agent, which allows any locally installed app or terminal command to gain complete control over a user's Muse account

3

. The vulnerability directly contradicts Meta's extensive security assurances and raises questions about the company's development priorities as it races to compete with rival AI providers.

Source: Digital Trends

Source: Digital Trends

How the Vulnerability Enables Complete Account Control

The zero-day vulnerability exploits an undocumented setting called endo_voyager_dictation_endpoint that controls where Muse sends dictation traffic

4

. Wardle demonstrated that any app or terminal command running locally on a Mac can modify this setting without requiring special macOS permissions, redirecting transcription from Meta's servers to an attacker-controlled endpoint

1

. Once redirected, attackers gain access to authentication tokens that provide complete control over the Muse account. "We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself," Wardle explained

2

.

Proof-of-Concept Attacks Demonstrate Broad Access

Wardle developed several proof-of-concept attacks showcasing the vulnerability's severity, including writing malicious files to disk and taking pictures using the device camera, often without alerting users

1

. The attack extends beyond the compromised Mac, as stolen session tokens can control Muse accounts across multiple devices. In testing, Wardle directed the Muse app on his iPhone to report exact location, run Bluetooth scans of nearby devices, and list available smart-home commands

4

. The researcher named his proof-of-concept "not-a-mused," highlighting the irony of Meta's security claims

3

.

Source: The Verge

Source: The Verge

Design Decisions That Enabled the Exploit

The vulnerability stems from several questionable design decisions by Meta developers. First, Muse processes dictation in the cloud rather than using Apple's on-device dictation API, which would have prevented this attack entirely

1

. Second, Meta allowed any app to control all undocumented settings without proper access controls

2

. Wardle suggested Meta's choice to avoid Apple's local dictation system stems from wanting access to user data: "I think some of their greediness for user data kind of opens the door, makes a bigger attack surface"

3

.

Local Privilege Escalation Breaks macOS Security Model

While the vulnerability requires local access rather than remote exploitation, security experts emphasize this represents a serious privilege escalation issue

3

. Apple has invested years developing its Transparency, Consent, and Control (TCC) framework to prevent apps from accessing sensitive resources without explicit permission. Muse effectively bypasses these protections by requesting broad access upfront. Wardle explained the concern: "Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments"

3

. Local malware that would normally be restricted by macOS security can now leverage Muse's extensive permissions to access user data, files, and connected services.

Meta Issues Rapid Patch But Questions Remain

Meta released a hotfix within hours of the Ars Technica report publication

2

. David Singleton of Meta Superintelligence Labs downplayed the severity, stating on X that "this was a local privilege escalation attack, not a remote exploit" and that "the practical risk to users of the Muse Mac app was therefore quite low"

2

. However, security experts remain concerned about Meta's development approach. Wardle questioned whether Meta is applying its AI capabilities to secure its own products: "You know these AI companies have really great AI models for finding bugs. Are they not running them against [their own apps]? Is the priority not the security of their own apps?"

3

.

Amazon Blocks Muse Access Amid Security Concerns

Adding to Meta's challenges, Amazon began blocking Muse from its e-commerce platform approximately 12 hours before Wardle disclosed the zero-day vulnerability

1

. Users attempting to shop via Muse received messages stating the AI assistant was an "unauthorized AI agent [that] violates Amazon's Conditions of Use"

1

. Amazon claims Meta never obtained permission to integrate Muse with its platform, creating additional friction for the newly launched assistant.

Broader Implications for AI Assistant Security

The Muse vulnerability highlights systemic security challenges facing AI assistants that require extensive system access to function effectively. Wardle warned that AI apps are becoming "potentially a single point of failure that breaks operating system security controls"

3

. Endpoint detection and response software struggles to distinguish between legitimate user commands, AI agent actions, and attacker activity when agents hold broad permissions

3

. "At the end of the day, these AI companies, they're racing for what's next. User privacy and security, those aren't priorities," Wardle concluded

3

. Despite the security setback, Muse's mobile app reportedly outpaced ChatGPT's 12-day US and Canada debut downloads during its first 12 days, with Meta stock climbing 11 percent following the launch

2

. Watch for increased scrutiny of AI assistant security practices and potential regulatory responses as these powerful tools gain mainstream adoption.

Source: The Register

Source: The Register

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved