A zero-day vulnerability has been discovered in Meta's Muse AI assistant that allows locally running applications or terminal commands to gain complete control over a user's account. The flaw, identified by macOS security expert Patrick Wardle, enables attackers to manipulate undocumented settings to change the endpoint where voice transcription occurs.
Meta's Muse AI Assistant Vulnerable to Zero-Day Exploit Allowing Full Account Control
While Muse is designed to handle tasks such as booking appointments and managing social media, it requires broad permissions on macOS to access files, microphones, and calendars. The vulnerability allows an attacker to redirect transcription requests to a malicious server, capturing the authentication token used for the Muse account. Wardle demonstrated proof-of-concept attacks that can write malicious files to disk or capture images without notifying the user.
"Instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself," Wardle told Ars Technica. He noted that the design choice to perform transcription in the cloud, rather than on-device, facilitated the exploit.
Concurrently, Amazon has begun blocking Muse from its platform. Users attempting to use the assistant for shopping on Amazon received messages stating that Muse is an "unauthorized AI agent" that violates the site's Conditions of Use. Amazon stated that third-party agents must respect the decisions of service providers to ensure a secure customer experience and has requested that Meta remove Amazon from the Muse experience.
Sources
- Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day (Hacker News Frontpage, 2026-09-22)