Meta’s Muse AI Assistant Vulnerability Exposes Users to Full Account Takeover

Meta’s new AI assistant Muse, touted for its privacy, has a zero‑day vulnerability that allows local apps or terminal commands to steal authentication tokens and hijack the assistant. The flaw enables attackers to redirect transcription to malicious servers, giving them full control of user account…

By Felo News Desk · Published

Meta’s Muse, the company’s latest AI assistant, was introduced a few weeks ago as a tool that can book appointments, fill out forms, handle customer service, make purchases, generate images, create documents, and connect with users’ favorite apps and services. The assistant runs on macOS and can integrate with WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse can create one on the fly, according to Meta’s own documentation.

Security Claims vs. Reality

Meta’s founder and CEO Mark Zuckerberg has repeatedly emphasized that Muse is “built from the ground up for privacy and security.” However, a zero‑day vulnerability discovered by macOS security expert Patrick Wardle contradicts those assurances. The flaw allows any locally run app or terminal command to obtain the authentication token that grants full access to a Muse account.

Because Muse runs on macOS, users must grant the assistant broad permissions: writing files to disk, accessing the microphone and camera, and monitoring location and calendars. Apple’s operating system is designed to prevent installed apps or terminal commands from accessing these resources without explicit user consent. Muse, however, bypasses these default protections. The vulnerability is rooted in a design decision that lets any app or command change a list of undocumented settings, including the endpoint used for transcription.

How the Attack Works

Under normal circumstances, Muse’s dictation is sent to a Meta‑operated server. The zero‑day flaw allows an attacker to redirect that traffic to a malicious endpoint. Once the transcription is processed by the attacker’s server, the authentication token is automatically forwarded, giving the attacker complete control over the Muse account. Wardle demonstrated the attack with a simple ClickFix technique that requires only a single terminal command.

Wardle’s proof‑of‑concept attacks include writing malicious files to disk and capturing photos without the user’s knowledge. Because the attacker can manipulate Muse’s privileges, they can perform any action the assistant can, effectively turning Muse into a powerful malware vector.

Amazon Responds and Meta’s Silence

About 12 hours before Wardle disclosed the vulnerability, Amazon began blocking Muse from its site. Users attempting to shop with Muse received a message stating that the assistant was an “unauthorized AI agent” that violated Amazon’s Conditions of Use. Amazon’s statement emphasized that third‑party applications offering to make purchases on behalf of customers must operate openly and respect the service provider’s decisions.

Meta has not responded to inquiries about the vulnerability. The company has published two posts outlining the design decisions that were intended to ensure privacy and security, but the posts do not address the zero‑day flaw. Wardle points out that Meta’s choices—such as routing dictation to the cloud and allowing any app to control undocumented settings—made the exploit possible.

Implications for AI Assistant Security

Wardle argues that the bar for security in AI assistants should be higher than in traditional software. While a compromised device can expose any app, the unique capabilities of an AI assistant like Muse amplify the risk. The assistant’s extensive access to user data and device resources means that a single vulnerability can lead to full account takeover.

Security researchers warn that the flaw could be exploited by malicious actors to harvest sensitive information, perform unauthorized purchases, or spread malware. Wardle plans to discuss the vulnerability in more detail at the Objective-See security conference in November.

What Happens Next?

Meta’s next steps remain unclear. The company has yet to release a patch or public statement. Users are advised to monitor updates from Meta and consider disabling Muse until the vulnerability is addressed. Amazon’s block suggests that other e‑commerce platforms may follow suit if the issue is not resolved.

As AI assistants become more integrated into daily life, the Muse incident highlights the need for rigorous security testing and transparent communication from developers. The incident also underscores the importance of keeping device operating systems and applications up to date to mitigate zero‑day exploits.

Key facts

  • Meta’s Muse can book appointments, fill forms, and make purchases. The zero‑day flaw lets local apps steal authentication tokens. Attackers can redirect transcription to malicious servers. Amazon blocked Muse from its site for violating usage policies. Meta has not yet responded or released a patch. The incident highlights the need for stronger AI security testing.

Why it matters

The Muse vulnerability demonstrates that even highly promoted AI assistants can contain critical security flaws, potentially exposing users to full account takeover and data theft. It underscores the necessity for robust security practices in AI development.

Frequently asked questions

What is Muse?

Muse is Meta’s AI assistant that can perform tasks like booking appointments, filling out forms, making purchases, and integrating with various apps and services on macOS.

How does the zero‑day vulnerability work?

The flaw allows any local app or terminal command to change undocumented settings, including the transcription endpoint, enabling attackers to redirect voice data to a malicious server and steal the authentication token.

What should users do?

Users should monitor Meta for a patch, consider disabling Muse until the issue is resolved, and keep their macOS and applications updated.

Sources

  • [1] arstechnica.com — originally reported as “Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day”

More from World

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com