Meta has released a hotfix for a 0-day vulnerability in Muse, its macOS AI assistant, after security researcher Patrick Wardle found that the flaw could let attackers use the assistant's privileges to control a victim's device and connected accounts.

Muse is designed to book appointments, complete forms, handle customer service and carry out tasks across services. It can also make purchases, generate s, create documents and connect with apps including WhatsApp, email, calendars and social media. The assistant creates tools when a required capability is not already available. There is no Windows version mentioned in the report.

Why the vulnerability mattered

To perform these actions, Muse requires access to user accounts and broad macOS permissions. Those permissions can include writing files to disk, using the microphone and camera, and monitoring location and calendars.

The vulnerability allowed any app or terminal command to access the token used to authenticate a user's Muse account. Locally installed software could also change undocumented Muse settings, regardless of its existing macOS permissions.

Most of those settings controlled relatively minor functions, such as dark mode. one setting changed the endpoint used for transcription. Muse normally sent transcription to a Meta-operated server, but an attacker could redirect that process to a server under their control. The attacker could then obtain the token and gain complete control of the Muse account.

Wardle told Ars that the flaw meant attackers could rely on Muse instead of building separate Mac malware to exploit its privileges. He said his proof-of-concept attacks could write malicious files to disk and take pictures, in some cases without a visible alert.

Cloud transcription and ClickFix risk

Wardle also criticised the decision to process Muse dictation in the cloud. macOS includes an on-device dictation and transcription option, which would have avoided the specific attack described in the report.

A separate concern involved the ability of any app or command to change Muse's undocumented settings. Allowing software to adjust interface preferences is different from allowing it to redirect the location where sensitive speech is processed.

The report said a simple variation of a ClickFix attack could be enough to take control of a Muse account. In Wardle's demonstration, a terminal command secretly sent a prompt to Meta's endpoint and triggered a response. A proxy server could also sit between the user and Meta, insert a malicious instruction into a voice prompt and receive the authentication token.

Wardle is the creator of the Objective-See Foundation, a macOS security nonprofit, and plans to discuss the vulnerability and other AI assistant risks at the Objective by the Sea security conference in November.

Meta response and Amazon dispute

More than 12 hours after the disclosure, Meta said it had issued a hotfix for the 0-day. The company described the vulnerability as “not a remote exploit.” The report said Meta did not address the role that ClickFix-style social engineering could play in triggering the attack or explain why Muse used cloud transcription instead of macOS's on-device option.

Amazon began blocking Muse shopping attempts roughly 12 hours before Wardle disclosed the vulnerability. Users received a message saying Muse was an “unauthorized AI agent” that violated Amazon's Conditions of Use.

Amazon said third-party applications that make purchases for customers should operate openly and respect service providers' decisions about participation. It asked Meta to remove Amazon from the Muse experience.

Conclusion

The Muse flaw exposed the security challenge created when an AI assistant combines broad device permissions with access to multiple user accounts. Meta has issued a hotfix, but the incident has raised questions about Muse's design choices, cloud-based transcription and the testing of assistants that can act on a user's behalf.

Frequently Asked Questions

Q. What is Muse?

Muse is Meta's macOS AI assistant, designed to complete tasks such as booking appointments, filling out forms, handling customer service and working with connected apps and services.

Q. What did the Muse 0-day allow?

The flaw could let an app or terminal command access the token authenticating a Muse account and redirect the endpoint used for transcription.

Q. What could attackers do with the token?

The token could give attackers complete control over the Muse account and allow them to use the assistant's privileges for actions such as writing files or taking pictures.

Q. Did Meta patch the vulnerability?

Yes. Meta said it released a hotfix more than 12 hours after the disclosure.

Q. What is ClickFix's relevance to the Muse flaw?

The report said a ClickFix-style attack could help trigger the vulnerability through a terminal command or a malicious prompt.

Q. Why did Amazon block Muse shopping?

Amazon said Muse was an unauthorized AI agent that violated its Conditions of Use and asked Meta to remove Amazon from the experience.

Q. Who found the vulnerability?

Patrick Wardle, a macOS security expert and creator of the Objective-See Foundation, discovered the 0-day.

Q. When will Wardle discuss the issue further?

Wardle said he plans to discuss the vulnerability and other AI assistant threats at the Objective by the Sea security conference in November.