Researcher Finds Meta Muse Flaw That Can Capture User Authentication Tokens

The flaw is not a remote break-in method, but it can turn code already running on a Mac into a route to an AI agent’s connected accounts and permissions.

By 2 min read
Researcher Finds Meta Muse Flaw That Can Capture User Authentication Tokens
Researcher Finds Meta Muse Flaw That Can Capture User Authentication Tokens

Listen to this story

The audio brief

About 1:34
0:001:34
Read transcript
Meta’s macOS Muse assistant has a zero-day that can expose its authentication token—but only after an attacker already has code running on the Mac. Security researcher Patrick Wardle found that any local app, or even a terminal command, can change an undocumented Muse setting regardless of that app’s own macOS permissions. One setting controls where Muse sends voice prompts for transcription. Redirecting it from Meta’s server to an attacker-controlled endpoint could reveal those prompts and the token Muse uses to authenticate the user’s account. Wardle demonstrated the risk with a proxy proof of concept. An attacker could place a malicious command inside a voice prompt, have Muse process it, and capture the token. That could give the attacker lasting control of the Muse account and its connected services. The distinction matters: this is not a remote break-in against a clean Mac. The attacker first needs a foothold, such as malware, a malicious app, or successful social engineering. But Muse concentrates unusually broad access. With permission, it can connect to WhatsApp, email, calendars, and social platforms, while also working with files, the microphone, camera, and location. Wardle also reported demonstrations that used Muse to write files and take photos, sometimes without visible alerts. Amazon has blocked Muse from shopping on its site over unauthorized agent use. The key question now is whether Meta tightens control over Muse’s transcription endpoint and permissions, without removing the assistant’s core capabilities.

Story brief

3 key points

Patrick Wardle disclosed a zero-day in Meta’s macOS Muse assistant that lets software already running locally alter an undocumented transcription-server setting. Redirecting Muse to an attacker-controlled endpoint can expose voice prompts and the assistant’s authentication token, enabling account takeover. The flaw requires an existing foothold—such as malware or a malicious app—rather than enabling remote...

  1. 01

    Muse’s transcription endpoint can be changed by local apps or terminal commands regardless of their macOS permissions.

  2. 02

    Wardle’s proxy proof of concept used a voice prompt to inject a malicious command and capture a token.

  3. 03

    Muse can connect to WhatsApp, email, calendars, social platforms, and support appointments, forms, purchases, and document creation.

Security researcher Patrick Wardle has disclosed a zero-day in Meta’s macOS Muse assistant that can let code already running on a Mac redirect the assistant’s transcription traffic and capture the user’s Muse authentication token. The result is a possible takeover path for an agent that can connect to personal accounts and use protected device resources.

The weakness lies in an undocumented configuration setting. Wardle found that locally installed apps or terminal commands can change Muse settings regardless of their own macOS permissions. One setting selects the server used for dictation transcription. Changing it from Meta’s server to an attacker-controlled endpoint can expose a person’s voice prompts and the token used to authenticate their Muse account.

A serious escalation, not a remote break-in

The issue is not a remote-code-execution vulnerability against an otherwise clean Mac. An attacker first needs local code execution, through malware, a malicious app, or social engineering. But once that foothold exists, Wardle described a proxy-based proof of concept in which an attacker inserts a malicious command into a voice prompt and captures the token, permanently compromising the Muse account.

What access could be concentrated in Muse

  • Muse is designed to handle appointments, forms, customer-service interactions, purchases, and document creation.
  • The assistant can connect to WhatsApp, email, calendars, and social platforms.
  • With user-granted permission, it may access files, the microphone, camera, location, and calendars on a Mac.

Meta introduced Muse only weeks before the disclosure as a macOS app. Its capabilities make the design choice around endpoint controls more consequential than a routine preference setting: the assistant can hold account connections alongside operating-system permissions granted for its work.

Proofs of concept show the potential reach

Wardle said he developed proof-of-concept attacks that used Muse’s privileges to write malicious files to disk and take pictures, often without visible alerts. Those demonstrations show the potential payoff of compromising the assistant after local access is obtained; they do not mean the flaw itself remotely compromises a Mac.

Editorial analysis

Our Read

Muse’s utility depends on combining account connections with access to a user’s computer. That same design concentrates value behind the assistant’s authenticated session: an attacker who reaches it may not need to separately extract every account connection or device permission. The immediate security issue is the transcription-endpoint control Wardle identified, not an ordinary remote takeover of a clean Mac. The consequential next step would be a change that prevents unprivileged local software from altering sensitive routing settings, especially in agents designed to work across personal communications and files.

Sources

  1. arstechnica.comMuse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
  2. malwarebytes.comMeta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor

Loading discussion...

YOUR READING SPACE

Notifications

Researcher Finds Meta Muse Flaw That Can Capture User Authentication Tokens | Superpower Daily