NG Solution Team
Cybersecurity

Muse AI vulnerability exposes Macs to hackers

Security researcher Patrick Wardle discovered a zero-day vulnerability in Meta’s Muse AI assistant for Mac that could let an attacker with code already running on a machine take control of the agent and abuse its access to sensitive data and device functions.

Muse’s access and the risk

Muse is designed to perform actions for users—booking appointments, filling forms, creating documents, making purchases and interacting with services such as WhatsApp, email and calendars—and on Mac it can also access files, messages, notes and Mail. Depending on granted permissions, Muse may reach resources including files, the microphone, camera, location and calendar. Wardle warned that, because of that broad access, compromising the agent could give an attacker a larger attack surface than an ordinary app: “We can manipulate the agent and leverage its privileges to do whatever we want,” he said.

How the flaw worked

The vulnerability involved an undocumented Muse configuration setting that controls where dictation transcription is processed. Muse normally sends dictation to a server for transcription, but Wardle found a way for a locally running application or terminal command to change that destination to an attacker-controlled server. An attacker who redirected transcription could capture voice prompts and obtain the authentication token tied to the victim’s Muse account; with that token the attacker could effectively control the Muse agent. Wardle also reported that locally installed apps were able to modify Muse’s undocumented settings, which worsened the exposure.

This proof-of-concept abuse could make Muse take pictures and write malicious files to the Mac, in some cases without alerting the user. Meta patched the vulnerability shortly after it was reported and issued a hotfix.

Local code required, not a remote exploit

The flaw was not a remote code execution vulnerability that would allow attackers to pick a Mac at random and take it over. An attacker first needed malicious code running locally on the computer—delivered by malware, a malicious app or social-engineering techniques. David Singleton of Meta Superintelligence Labs described the issue as a local privilege‑escalation attack rather than a remote exploit, and said the practical risk was reduced because the machine would already need to be compromised.

But Wardle and others note that getting malware onto a Mac is a realistic threat: infostealers and social-engineering methods such as tricks that persuade users to run commands are already in use. Once local code runs, Muse could provide a more convenient interface for that code to reach resources the user has authorized.

What Mac users should do

Wardle’s advice was simple: do not install Muse. For users of any AI agents, limit permissions to only what the agent needs and regularly review connected accounts and access. Be cautious about instructions embedded in webpages, emails or documents—those instructions are not automatically trustworthy just because an AI agent can read them. Watch for unusual agent behavior, such as sudden permission requests, account reauthentication prompts, unexpected external file sharing or actions you did not initiate.

Above all, maintain basic Mac security: keep software updated, use reputable real-time malware protection and avoid following unsolicited instructions to paste commands into Terminal.

Sources: Malwarebytes, The Verge

Related posts

Muse zero-day Vulnerability in Mac Assistant Risks User Data

James Smith

Hotel WiFi Hijacked by Russian Hackers, Microsoft Warns

David Jones

US suspends Michoacán avocado inspections after security alert

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy