Meta fixed a zero-day vulnerability in the Muse AI assistant that allowed takeover of a user's account
Meta released a hotfix for a zero-day vulnerability in the macOS Muse app, discovered by researcher Patrick Wardle. The flaw allowed any local process to redirect speech transcription to a foreign server and thereby obtain an authentication token for full account takeover.
Meta released a hotfix for the macOS Muse app that fixes a zero-day vulnerability discovered by security researcher Patrick Wardle. The flaw allowed any locally running process or terminal command, regardless of what permissions macOS had granted it, to change undocumented Muse settings — including the endpoint to which the app sends audio for speech transcription. An attacker could redirect this endpoint to their own server and thereby obtain an authentication token granting full control over the Muse account. According to Meta, the hotfix was released more than 12 hours after Ars Technica published its report.
Wardle created working proof-of-concept attacks that, using the agent's abused permissions, were able to take photos with the camera or write malicious files to disk without any notification to the user. According to Wardle, this was a consequence of Meta's decision to process dictation and speech transcription on a server rather than directly on the device, while also allowing any application to control all of Muse's undocumented settings, including a parameter as sensitive as the target server for speech transcription. David Singleton of Meta Superintelligence Labs stated regarding the attack that it was a local privilege escalation rather than a remote exploit, and that the company therefore assesses the practical risk to users as low — but it released the hotfix anyway.
The disclosure of the vulnerability came roughly 12 hours after Amazon began blocking Muse during purchases on its website, citing it as an unauthorized AI agent violating the terms of service, and asked Meta to remove it. According to available data, despite this Muse was downloaded by more users in its first 12 days after launch than the ChatGPT app gained in the United States and Canada during the same period, and Meta's stock subsequently rose by 11 percent.
Why it matters
For Muse users, this represented a real risk of complete loss of control over their account and private data (photos, files, messages) without any warning, until Meta fixed the issue. For developers and companies deploying agentic AI with deep access to the operating system and accounts, this is a concrete example that the security design of such tools (e.g., where sensitive data processing takes place and who can change settings) must be addressed from the very beginning — otherwise there is a risk of the agent itself being abused as an attack tool, as well as rejection by partner platforms.
What was added since the original report
Verified updates
-
Any local process could access the authentication token without macOS permissions; An attacker could change the transcription endpoint to their own server and take over the account; Patrick Wardle created working proof-of-concept attacks for demonstration purposes; The goal of the exploit was to obtain the authentication token, not direct control of the agent
- Any local process could access the authentication token without macOS permissions
- An attacker could change the transcription endpoint to their own server and take over the account
- Patrick Wardle created working proof-of-concept attacks for demonstration purposes
- The goal of the exploit was to obtain the authentication token, not direct control of the agent
Two audiences, two different impacts
What this means
For individuals
Until the hotfix was released, users of the macOS Muse app were at risk of complete takeover of their account, secret photo capture via the camera, and malicious files being written to disk — all without any warning.
For a business
The case illustrates the risk for companies considering integrating or deploying AI agents with broad permissions to systems and user accounts — weak security in such an agent can also harm partner platforms, as happened with Amazon, which blocked Muse from its website.
Risks and complianceCheck the original
Event sources
confirmed by 2 independent sources · 2 publishers, 2 independent. We count feeds from the same owner only once.