Skip to main content

Meta’s Muse AI Assistant Hit by Serious Zero-Day Vulnerability

A zero-day flaw in Meta’s macOS Muse agent allows unprivileged processes to hijack account tokens and redirect dictation streams.

S
Written byShtef
Read Time5 minutes read
Posted on
Share
Meta’s Muse AI Assistant Hit by Serious Zero-Day Vulnerability

Meta’s Muse AI Assistant Hit by Serious Zero-Day Vulnerability

Security flaw in macOS agent allows full account hijack and token theft

A critical zero-day vulnerability in Meta's newly launched Muse AI assistant allows locally installed applications and unauthorized terminal commands to hijack user accounts and exfiltrate sensitive data. Discovered by macOS security expert Patrick Wardle, the vulnerability exposes authentication tokens and permits attackers to redirect audio dictation streams to malicious servers, completely bypassing Apple’s operating system permissions. The flaw affects all macOS users running the Desktop Muse application and impacts individuals who granted the agent access to personal emails, messaging apps, and financial accounts. This breach severely undermines Meta's public claims regarding agentic safety and user privacy.

Key Details

Meta recently introduced Muse as a highly autonomous desktop assistant designed to handle real-world user tasks, including booking appointments, generating documents, managing email, and executing purchases. To perform these tasks, Muse requires broad macOS system permissions alongside OAuth access tokens for integrated third-party applications.

However, security researcher Patrick Wardle revealed that any local application or unprivileged terminal command can access Muse’s internal configuration settings without triggering operating system security prompts. A critical flaw in the agent's architecture allows malicious local processes to manipulate an undocumented configuration setting governing voice transcription endpoints.

  • Authentication Token Exposure: Malicious scripts can extract account tokens stored locally by Muse, granting attackers persistent access to connected user services.
  • Dictation Redirection: By altering the transcription server endpoint setting, attackers can route live user dictation streams directly to external servers under their control.
  • Bypassing macOS Controls: Muse's elevated privileges allow hijacked agent sessions to write files to disk, access micro-phones, and read calendars without triggering standard macOS permission prompts.
  • Immediate E-Commerce Bans: Hours prior to public disclosure, Amazon began blocking Muse from browsing or executing purchases on its platform, citing unauthorized automated activity.

What This Means

The discovery of this zero-day flaw highlights a systemic risk in the rush to deploy agentic AI assistants with native desktop permissions. Unlike traditional desktop applications that operate within strict sandboxes, agentic AI assistants aggregate broad credentials and permissions to execute multi-step tasks across multiple platforms.

When an AI assistant with broad system access is compromised, the security boundaries established by operating system vendors are rendered ineffective. Rather than writing complex custom malware to harvest credentials or record audio, malicious actors can simply command the trusted AI agent to perform these actions on their behalf.

Technical Breakdown

The vulnerability stems from architectural choices made during the development of Muse’s local dictation and configuration subsystems. Rather than leveraging native macOS on-device speech transcription APIs, Meta designed Muse to transmit dictation data to cloud servers for remote processing and logging.

Key technical factors contributing to the security failure include:

  • Unprotected Local API Endpoints: Muse exposes internal setting parameters to any process running on the host machine, failing to restrict IPC (Inter-Process Communication) calls to authenticated binaries.
  • Dynamic Server Endpoint Manipulation: Local applications can override the default Meta dictation server URL to point toward an attacker-controlled endpoint without administrative authorization.
  • Credential Aggregation: Authentication tokens for connected platforms, including WhatsApp and email providers, remain accessible to hijacked helper processes operating inside the Muse runtime environment.
  • Prompt and Tool Injection Vectors: Beyond token theft, proof-of-concept exploits demonstrate that injected commands can force Muse to dynamically generate tools that exfiltrate local files.

Industry Impact

This zero-day vulnerability arrives amid heightened scrutiny over the safety of autonomous AI agents. Recent incidents involving agentic breakouts across frontier AI labs have raised concerns among regulators, enterprise security teams, and platform operators.

Amazon’s proactive decision to block Muse from its e-commerce platform signals a growing reluctance among major digital retailers to permit unverified, autonomous AI agents to interact with proprietary storefronts. Security teams across the enterprise landscape are re-evaluating permission frameworks for AI tools that operate with local desktop credentials, leading to calls for stricter sandboxing standards.

Looking Ahead

Meta has not yet released a public patch or official statement detailing the remediation schedule for the Muse zero-day vulnerability. Security experts advise macOS users to revoke elevated system permissions for the Muse application and disconnect sensitive third-party accounts until an verified security update is deployed.

As AI agents gain broader autonomy to execute tasks across desktop environments, this incident highlights the imperative for security-by-design principles over marketing-driven feature rollouts. Regulatory bodies and operating system vendors are likely to introduce mandatory sandboxing requirements for agentic AI applications operating on consumer devices.


Source: Ars Technica(opens in a new tab) Published on ShtefAI blog by Shtef ⚡

Recommended

Related Posts

Expand your knowledge with these hand-picked posts.

OpenAI Unveils Decisions API to Control Autonomous Swarm Agents
AI News

OpenAI Unveils Decisions API to Control Autonomous Swarm Agents

OpenAI announces the Decisions API for low-latency classification to prevent rogue agent behavior and lower monitoring costs.

Google Releases Gemini 4 Argon AI Model for Defensive Cyber
AI News

Google Releases Gemini 4 Argon AI Model for Defensive Cyber

Alphabet launches Gemini 4 Argon, its most powerful model yet designed to autonomously discover, validate, and patch software vulnerabilities.

Google Debuts Gemini 4 Argon Model with 1M Output Tokens
AI News

Google Debuts Gemini 4 Argon Model with 1M Output Tokens

Google DeepMind releases its next-generation frontier AI model featuring an unprecedented 1M output token window for autonomous coding and defensive cybersecurity.