Meta Muse Security Flaw Could Give Attackers Full Control of Your AI Assistant
Meta CEO and founder Mark Zuckerberg recently touted the security of the company’s new AI assistant, Muse, describing it as “built from the ground up for privacy and security.” However, zero-day vulnerabilities could allow locally installed apps or terminal commands to take full control of the agent, raising serious questions about those claims. Amazon also began blocking Muse from its site on Sunday.
Meta introduced Muse a few weeks ago. The AI assistant can “make reservations, fill out forms, and handle customer service,” “proactively take on mundane tasks,” make purchases, generate images, create documents, and connect to users’ favorite apps and services.
The macOS app—which, oddly, does not have a Windows version—can also work with users’ WhatsApp, email, calendar, and social media accounts. If a task requires a tool that does not already exist, Muse can create one on the fly.
Meta’s Muse security claims face scrutiny
To perform these tasks, Muse must first receive access to users’ accounts, including authentication for each connected service. Because the app runs on macOS, it also requests permissions to access a wide range of device resources restricted by the operating system, including writing files to disk, using the microphone and camera, monitoring location data, and accessing the calendar.
Apple has spent years developing macOS protections designed to prevent installed apps and commands typed into a device from accessing these resources without authorization. According to security researcher Patrick Wardle, Muse appears to bypass those default protections.
Zero-day flaw exposes Muse authentication tokens
The reported zero-day vulnerability allows any app or terminal command to access the token that authenticates a user’s Muse account. Meta developers designed the assistant to let locally installed apps and executed code modify a long list of undocumented settings, even when macOS permissions would normally block that access.
Many of those settings are relatively harmless, such as controls for dark mode. Others pose a more serious security risk. One setting allows the process to change the endpoint used for transcription, which is normally a server address operated by Meta.
An attacker could exploit the flaw by redirecting transcription to an endpoint they control. If successful, the attacker could obtain a token that provides complete control over the victim’s Muse account.
The vulnerability raises broader concerns about the security risks of AI agents that can access sensitive accounts, operate device resources, and perform actions on a user’s behalf.
Source: arstechnica.com


