Despite Mark Zuckerberg's claims that Meta's new AI assistant, Muse, was built for privacy and security, a serious zero-day vulnerability revealed that the app left Mac users exposed to complete control by attackers. The flaw, discovered by macOS security expert Patrick Wardle, allowed local apps and terminal commands to bypass Apple's security measures and access sensitive data.
Anatomy of the Vulnerability
Muse, which handles tasks such as booking appointments and making purchases, requires broad access to email accounts, calendars, and system resources like the microphone and camera. The vulnerability allowed any malicious code to steal the user's authentication token. Furthermore, attackers could change the transcription endpoint, sending the user's voice prompts to their own servers instead of Meta's.
Wardle noted that Meta chose to perform transcription in the cloud rather than using Apple's built- on-device secure features. This design decision made the attack possible, which could be triggered even through simple social engineering techniques like "ClickFix" attacks.
Reactions from Meta and Amazon
Meta issued a hotfix approximately 12 hours after the story went live, claiming the vulnerability was not a "remote exploit." However, Amazon had already moved to block Muse from its site, labeling it an "unauthorized AI agent" that violates its terms of use.
According to Amazon, third-party applications making purchases on behalf of customers must operate openly and respect service provider decisions. This move adds another hurdle to Meta's attempt to establish Muse as a reliable digital assistant.