Meta’s Muse AI assistant has a serious security flaw, and the company’s own claims about how it was built now look questionable. A zero-day vulnerability found by macOS security expert Patrick Wardle gives any locally run app or terminal command complete control over the assistant. That means an attacker could take over a user’s account simply by changing where its speech transcription happens.
What Muse Does
A few weeks back, Meta launched Muse, an assistant that handles bookings, form-filling, customer service, and purchases. It also produces images, crafts documents, and links up with a user’s WhatsApp, email, calendar, and social media accounts. The macOS app comes without a Windows version.
Muse builds tools on demand when a job calls for something that hasn’t been made yet. Before any of this happens, users need to let the assistant into their accounts by verifying it with each service and granting it macOS permissions to write to disk, use the mic and camera, and watch over location and calendars.
The Zero-Day Vulnerability
Before the fix was rolled out, Wardle told Ars that the flaw gave any app or terminal command permission to grab the token that proves a user’s identity to their Muse account. He explained that Meta developers built the assistant with no safeguards, so that any locally installed app or piece of code could change a long list of settings without needing macOS permissions, no matter what the system might otherwise allow.
The majority of those settings are harmless, such as managing dark mode. One, though, was far from it. It gave processes permission to alter the endpoint where transcription happens. Ordinarily, that endpoint is a server address run by Meta. A person acting with harmful intent could have redirected it to their own endpoint instead, thereby obtaining the token that grants full command over the Muse account.
“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle said. “So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.”
He claimed to have built several working attacks that can put harmful files on a drive and take photos, usually without giving any sign of their activity to a person paying close attention.
Design Decisions That Made the Exploit Possible
According to Wardle, the exploit was made possible by design choices made by Meta developers. One such choice involved Muse dictation taking place in the cloud, where Meta can log it. macOS has long offered a straightforward way for apps to manage dictation and transcription entirely within processes kept secure on the device itself.
Had the developers chosen that safer alternative, the attack wouldn’t have been possible. Another flawed decision is allowing any app to control all of the undocumented settings. It’s likely Meta intended for apps working with Muse to control UI settings, and for understandable reasons. The ability for any app or command to control an endpoint where sensitive user speech is processed is an entirely different matter.
The choices made for the assistant’s design prompt a great deal of doubt about how much work developers put into building and testing its security and privacy features.
“To me, the bar is infinitely higher in terms of the security of these apps,” Wardle said. “They don’t have to be perfect, but when you take a look at Muse, it’s like they didn’t, in my opinion, think about security, which is really worrisome. At the very least, they should be thinking about security from the very start, and they are just not.”
Amazon Blocks Muse From Its Site
About 12 hours after the post appeared, Meta announced a hotfix that fixed the zero-day vulnerability. Just roughly 12 hours before Wardle revealed the flaw, Amazon began preventing people from using Muse to shop on the site. Anyone who attempted to do so got a message saying Muse was an “unauthorized AI agent [that] violates Amazon’s Conditions of Use.”
The statement from Amazon says the change guarantees a secure, reliable, and safe customer experience, and follows the way other services work, including food delivery apps and the stores they shop from. Amazon has requested that Meta remove Amazon from the assistant’s experience.
The Hypocrisy of Meta’s Security Posts
In just two weeks, Meta has released two posts detailing the choices made to keep an assistant with remarkable access to user data and resources safe and private. These posts appeared alongside reports that tests of models from Anthropic and Google led to security breaches of outside, third-party networks that the engineers involved never meant to target.
Criminal charges would probably follow such actions in the older kind of hacking done only by people. The Meta posts appear aware of the backlash that might come with it and the push to hold back AI development that could follow.
A Comparison of the Design Decisions
| Decision | Risk |
|---|---|
| Cloud-based dictation | Allows Meta to log user speech |
| Undocumented settings controlled by any app | Gives apps unreviewed power over the assistant |
| Server-controlled transcription endpoint | Can be redirected by attackers |
| Local transcription on macOS | Safer but not used by Meta |
The table makes clear how each design choice carries consequences for the rest. Every decision opens a door that another choice doesn’t fully seal.
The patch fixes the zero-day vulnerability, yet the design choices that created it persist. A helper program running on a user’s device with wide access and undisclosed settings presents a hard problem to resolve once the product has shipped.
Muse users should weigh whether they feel comfortable keeping the app active, given how much access the assistant holds over personal information. The company’s security assurances now sound doubtful, and that is worth considering before deciding whether to continue using the feature.
Source material: “Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw,” WIRED.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

