Updated
Updated · WIRED · Sep 23
Meta Patches Muse Zero-Day That Let Local Apps Seize Full Account Control
Updated
Updated · WIRED · Sep 23

Meta Patches Muse Zero-Day That Let Local Apps Seize Full Account Control

3 articles · Updated · WIRED · Sep 23

Summary

  • A hotfix released more than 12 hours after disclosure closed a Muse flaw that let any local macOS app or terminal command hijack a user's authenticated assistant session.
  • Patrick Wardle found Muse exposed a token by allowing unprivileged processes to change the transcription endpoint, so attackers could redirect voice data to their own server and gain persistent control.
  • Proof-of-concept attacks used Muse's broad permissions to write files, snap photos and issue malicious prompts, with Wardle saying even a simple ClickFix-style social-engineering trick could trigger the exploit.
  • Meta's security claims face added scrutiny because Muse can access WhatsApp, email, calendars and device resources, and Wardle said cloud-based transcription and permissive undocumented settings made the bug possible.
  • Amazon had already started blocking Muse from shopping on its site about 12 hours before Wardle's disclosure, calling it an unauthorized AI agent and asking Meta to remove Amazon from the experience.

Insights

Why did Meta's privacy-focused AI assistant bypass Apple's secure on-device dictation in favor of a vulnerable cloud connection?
Will Amazon's ban on Meta's Muse trigger a massive industry war against autonomous AI shopping agents?
Could a simple social engineering trick turn your highly privileged AI assistant into a silent data-stealing spy?