Meta Hyped Muse's Security. A Zero-Day Let Attackers Hijack Dictation and Take the Agent
A zero-day in Meta's Muse macOS assistant let any local app redirect its dictation endpoint and steal the auth token, handing attackers the whole account. Meta shipped a hotfix about 12 hours after disclosure.

Mark Zuckerberg pitched Muse, Meta's new macOS AI assistant, as "built from the ground up for privacy and security." Then a researcher showed that any app or terminal command on the machine could quietly take the whole thing over.
The assistant is unusually powerful, which is the point and the problem. Muse books appointments, fills out forms, makes purchases, and connects to a user's WhatsApp, email, calendar, and social accounts. To do that on macOS it holds broad system permissions: writing files, reaching the mic and camera, and watching location and calendars. It effectively undoes the defenses Apple spent years building to keep local apps away from exactly those resources.
Patrick Wardle, who found the flaw, described the mechanism to Ars Technica. Meta let any locally installed app or executed code change a long list of undocumented Muse settings. Most are harmless, like toggling dark mode. One is not. It controls the endpoint where Muse sends speech for transcription, normally a Meta server. Point that endpoint at an attacker's server and the Muse authentication token follows.
Once the token leaks, the account is theirs. "We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself." His proof-of-concept attacks wrote malicious files to disk and snapped pictures, in many cases with no sign visible even to an alert user.
The usual defense for bugs like this is that they need local code execution, so all bets are already off. Wardle argues that bar does not fit here. A simple variation of the ClickFix trick, the social-engineering scam that has become disturbingly effective at getting people to run a command themselves, is enough to trigger it. There is no classic remote code execution required, just a user talked into pasting one line.
Wardle is not a random poster. He runs the Objective-See Foundation, a nonprofit focused on macOS security, wrote "The Art of Mac Malware," and previously worked at NASA and the National Security Agency. He plans to detail the vulnerability and other AI-assistant threats at the Objective by the Sea conference in November.
Two design choices made the exploit possible. Muse handles dictation in the cloud, where Meta can log it, rather than using the on-device transcription macOS has offered for years. And it lets any app control all of those undocumented settings, including the one governing where sensitive speech is processed. The pairing turned a UI convenience into an account takeover.
Meta shipped a hotfix more than 12 hours after the Ars report went live, and pushed back on the framing. David Singleton of Meta Superintelligence Labs wrote on X that this was a local privilege escalation, not a remote exploit, so the practical risk was "quite low" because malicious code must already be running under the user's account. The Verge noted the launch has otherwise gone well for Meta, with early Muse downloads reportedly outpacing ChatGPT's US and Canada debut and the stock up 11 percent Monday.
The trust question is the same one dogging every over-privileged agent. When a single leaked token hands over files, camera, and connected apps, the blast radius looks a lot like the ChatGPT sandbox cross-account leak and the one-click VS Code workspace trust bypass: a small break in the plumbing, an outsized reach into everything the assistant can touch.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free