AIO APEX

Meta rushes out a hotfix after a zero-day let any app hijack its Muse AI agent

9to5Mac
Share:
Meta rushes out a hotfix after a zero-day let any app hijack its Muse AI agent

Meta shipped an emergency hotfix for its Muse personal AI agent on Mac on September 22 after macOS security researcher Patrick Wardle disclosed a zero-day vulnerability that let any locally running app or Terminal command hijack the assistant's authentication and take actions on a user's behalf, including snapping photos and writing files to disk without warning.

The timing is awkward for Meta. The company spent the two weeks since launching Muse for Mac promoting the agent's security architecture — a dedicated Secure VM, a monitoring system called Sentinel, and bug bounty rewards of up to $300,000 — with Mark Zuckerberg publicly stating the agent was "built from the ground up for privacy and security." Wardle named his proof-of-concept "not-a-mused," a dig at that framing.

Muse launched publicly on September 8 and expanded to Mac on September 17 as a step up from a chatbot: an agent meant to send emails, fill out forms, handle payments, and make purchases on a user's behalf, which requires handing it broad access to apps and accounts.

How the flaw worked

Wardle found that any process running locally under the logged-in macOS user — no elevated permissions required — could modify a set of undocumented Muse configuration settings, including one called endo_voyager_dictation_endpoint, which controls where the app sends a user's dictated voice prompts for processing. Redirecting that endpoint to an attacker-controlled server meant the next dictated prompt would leak the token authenticating the user's Muse account, handing the attacker control of the agent itself.

Wardle's proof-of-concept attacks wrote malicious files to disk, took photos through the Mac's camera, and pulled the real-time location of a linked iPhone — all without the user's knowledge. Wardle also pointed out that Apple already provides an on-device dictation API that would have avoided the issue entirely; Muse instead routes voice data to Meta's servers, which is what made the endpoint hijackable in the first place.

Local flaw, remote-capable exploit

Meta initially treated this as a local-only attack, since a would-be attacker needs to already be running code on the victim's Mac. But Wardle later clarified on X that a simple ClickFix-style attack — tricking a user into pasting a command into Terminal, a technique that has become the most common way malware reaches Macs — was enough to deliver the exploit remotely, giving an attacker full control over any device running Muse.

Meta pushed a fix roughly 16 hours after disclosure. Separately, and apparently unrelated to the vulnerability, Amazon has begun blocking Muse from making purchases on its site, another sign that other companies are treating agentic AI assistants as a new category of risk rather than a convenience to wave through.

Why it matters

Muse is one of the first mainstream consumer AI agents granted this level of access to a user's files, messages, and payment methods, and the flaw shows how a single undocumented setting can undermine an otherwise heavily marketed security stack. For any company shipping an agent with broad local permissions, the lesson is the same one Wardle has made in prior research: the weakest link is rarely the AI model itself, but the mundane configuration surface around it. Mac users running Muse should update to the latest version immediately.

Originally reported by 9to5Mac. Read the original article for additional details.

View original source
Share: