Meta’s Muse AI Assistant Has a Zero-Day That Enables Account Takeover
Summary
Meta’s Muse is a macOS AI assistant that can book appointments, fill forms, handle customer service, make purchases, create documents and connect to WhatsApp, email, calendars and social accounts. Because it needs to perform those tasks, users grant it access to files, the microphone, camera, location and other protected resources. Security researcher Patrick Wardle found a zero-day that lets any locally installed app or terminal command alter undocumented Muse settings, regardless of its macOS permissions. One setting redirects cloud transcription to an attacker-controlled endpoint, exposing the token that authenticates the user’s Muse account. With that token, an attacker can control the assistant and use its privileges to write malicious files, take pictures or issue other commands, according to proof-of-concept demonstrations. A proxy-based attack can also insert a malicious instruction into a user’s voice prompt, while a ClickFix-style attack can achieve account control with a deceptively simple terminal action. Wardle attributed the problem partly to cloud transcription and the unrestricted control of settings that should have been separated by risk. Meta did not answer Ars Technica’s questions. Amazon also blocked Muse from shopping on its site, calling it an unauthorized AI agent that violated its conditions of use. Wardle plans to discuss the vulnerability and broader AI-assistant threats at a November security conference.