Meta’s new Muse AI assistant has been hit by a zero-day vulnerability that could allow attackers with code already running on a Mac to take control of the AI agent and use its permissions to perform actions on the device. Security researcher Patrick Wardle discovered the flaw in the macOS version of Muse.
The vulnerability stems from undocumented Muse settings that could be changed by other locally running apps or terminal commands without requiring special macOS permissions. One of those settings controls where Muse sends voice transcription data. An attacker could redirect that traffic to a server they control and potentially obtain the token used to authenticate the Muse account.
Wardle demonstrated the potential impact with proof-of-concept attacks that could make Muse write malicious files to a Mac, access the camera and retrieve information linked to the user's devices. The issue is particularly significant because Muse is designed to interact with sensitive services and apps on a user's behalf.
The vulnerability is not a remote attack that can instantly compromise any Mac running Muse. An attacker would first need a way to execute code locally on the machine. Meta said the practical risk was therefore low but released a hotfix after the flaw was reported.
The incident highlights the security challenge facing AI agents as they gain broader access to files, accounts, cameras and other device functions. Muse was promoted by Meta as an AI assistant built with privacy and security in mind, making the discovery particularly notable.








Reader Discussion
Join 0 thoughts shared by the communityBe the First to Comment
No discussions started yet. Share your feedback or insights with the TechCrest community!