Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
Zero-day in Meta's Muse macOS AI assistant let any local app redirect transcription and steal account-control tokens; Meta released a hotfix.
macOS security researcher Patrick Wardle disclosed a zero-day in Meta's Muse AI assistant that allowed any locally installed app or terminal command, regardless of macOS permissions, to change undocumented settings including the transcription endpoint. Redirecting that endpoint to an attacker-controlled server exposed the token granting complete control of the Muse account and enabled prompt manipulation, file writes, and camera access with no user indication. Meta released a hotfix roughly 12 hours after disclosure, and Amazon separately began blocking Muse from its site as an unauthorized AI agent.