← All stories

Meta patches Muse AI assistant after zero-day let attackers seize the agent

No. 20·493 words·2 min

Meta issued a patch for its Muse macOS app after a security researcher demonstrated a zero-day vulnerability that could let someone running local code take full control of the AI agent, using its own broad permissions against the user.

Security researcher Patrick Wardle found that an undocumented Muse setting let potential attackers redirect transcription processing from Meta's servers to their own endpoint, according to Ars Technica. From there, an attacker could manipulate the agent and leverage its privileges — which, on macOS, include writing files to disk, accessing the microphone and camera, monitoring location and calendars, and authenticating to the user's WhatsApp, email, and social media accounts. Wardle built proof-of-concept attacks that took pictures and wrote malicious files through Muse, in many cases without alerting the user.

"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars Technica. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself."

The flaw stemmed in part from design decisions that Ars Technica flagged when it reported the vulnerability: Muse handles dictation in the cloud rather than on-device, and any app running locally could control all of Muse's undocumented settings. Apple has spent years building defenses that prevent installed apps and terminal commands from accessing restricted device resources. Muse, by design, undoes those default measures — the assistant needs that access to book appointments, fill out forms, make purchases, and connect with a user's accounts across services.

Meta patched the vulnerability within hours of the Ars Technica report being published. David Singleton of Meta Superintelligence Labs said on X that the exploit required local access — malicious code already running on the user's machine — and called the practical risk to users "quite low." He described it as a local privilege escalation attack, not a remote exploit.

The patch arrives as Muse is under scrutiny on other fronts. Amazon blocked the assistant from its e-commerce platform, claiming Meta never obtained permission to integrate with it. Meta has not publicly responded to that claim.

Muse launched earlier in September and has been downloaded faster than ChatGPT was in its first 12 days on mobile in the U.S. and Canada, according to estimates from the market intelligence firm Apptopia. Over 95 percent of Muse's users are also Facebook users, and 63 percent are Instagram users — a reach Meta built by cross-promoting the app across its largest platforms. Meta has not released its own download figures.

Wardle's finding cuts against the emphasis Meta placed on Muse's privacy and security when it announced the assistant. Mark Zuckerberg had called it "built from the ground up for privacy and security." The exploit demonstrated that a single undocumented setting, reachable by any local app, could turn the assistant into a vehicle for its own permissions — the same permissions that make Muse useful enough to draw millions of users in its first two weeks.