Security Flaw Discovered in Muse macOS App
Meta has issued a patch for its Muse application designed for macOS following the discovery of a zero-day vulnerability. The flaw, identified by security researcher Patrick Wardle, could potentially allow unauthorized individuals to gain control of the AI agent. The vulnerability was reportedly linked to an undocumented setting within Muse.
According to reports, the exploit required local access to the user’s device, but provided potential attackers with access to the user’s Muse accounts. The bug allowed locally executed code to reroute the transcription processing, diverting it from Meta’s official servers to an endpoint controlled by the attacker, thus compromising the Muse account.
Flaws and Exploitation Capabilities
Experts pointed to several design choices that reportedly contributed to the security weakness. These included the decision to conduct Muse dictation in the cloud rather than keeping it solely on the device, and the feature allowing any application to manipulate all of Muse’s undocumented settings.
Wardle developed proof-of-concept attacks to demonstrate the exploit’s potential. These tests allowed him to write malicious files to the disk and take pictures using Muse, often without the user receiving any warning.
Wardle stated his findings, noting the ease of manipulation:
We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.
At the very least, they should be thinking about security from the very start, and they are just not.
Meta’s Response and Commercial Context
Following the publication of the report, Meta quickly applied a hotfix to the application. David Singleton of Meta Superintelligence Labs addressed the vulnerability, clarifying that it constituted a local privilege escalation attack, not a remote exploit. He maintained that the practical danger to users of the Muse Mac app was low, as exploiting the vulnerability necessitated malicious code already running on the user’s machine under their user account.
The security incident occurred despite Meta’s earlier marketing efforts emphasizing the privacy and security features of the AI agent. Commercially, the exploit surfaced as Meta’s AI agent faced increased scrutiny from rival AI providers. Additionally, Amazon recently prevented Muse from accessing its e-commerce platform, claiming Meta had not obtained the necessary permission. Despite these challenges, the launch has seen strong commercial success for Meta. Estimates indicated that during its first 12 days, the Muse mobile app’s downloads surpassed ChatGPT‘s own 12-day debut figures in the United States and Canada. On Monday, Meta’s stock experienced an 11 percent climb.