Despite Mark Zuckerberg’s claims that Meta’s new AI assistant, Muse, was “built from the ground up for privacy and security,” a serious zero-day vulnerability has surfaced. The flaw allows locally run applications and terminal commands to gain complete control over the agent, which operates with extraordinary privileges on macOS.

Anatomy of the Zero-Day

Security expert Patrick Wardle discovered that any locally executed code can modify a long list of undocumented Muse settings. One specific setting allows attackers to redirect the endpoint where voice transcription occurs. By changing this address from Meta’s server to their own, attackers can intercept the authentication token, granting them total control over the user’s Muse account.

Wardle noted that instead of developing complex malware, attackers can simply leverage the AI assistant itself to perform malicious actions. Because Muse is integrated with WhatsApp, email, calendars, and has permissions for the microphone and camera, it effectively bypasses years of macOS security enhancements designed to restrict app access to such resources.

Design Flaws and Amazon’s Block

According to Wardle, Meta’s decision to perform dictation in the cloud—rather than using macOS’s native, on-device processes—made this exploit possible. Furthermore, allowing any application to control sensitive settings suggests a lack of rigorous security testing during development.

Amidst these security concerns, Amazon has begun blocking Muse from its site. Users attempting to shop via the assistant received messages stating it is an “unauthorized AI agent” that violates Amazon’s Conditions of Use. Amazon stated that third-party applications making purchases must operate openly and respect the service provider's decisions.

  • Muse creates custom tools on the fly when required tasks lack existing ones.
  • The zero-day allows for surreptitious file writing and photo capture.
  • A variation of the ClickFix attack is sufficient to hijack the assistant.