Meta launched its new AI assistant Muse to much fanfare earlier this month.
Now, just a few weeks later, a zero-day vulnerability has reportedly been discovered that could put access to your entire Mac computer in the wrong hands. (Meta currently does not have a Windows version of Muse for PC.)
macOS security expert Patrick Wardle posted on X about the vulnerability with the Muse app. According to Wardle, and as first covered by Ars Technica, the vulnerability lets "local malware/attackers invisibly hijack" a user's Mac.
This Tweet is currently unavailable. It might be loading or has been removed.
Wadle explains that thanks to the macOS permissions that Muse requires, an attacker could access and change the endpoint where transcription for dictation occurs. The server address is pointed to one that belongs to Meta, but with this change, the attacker could then gain access to the token that controls the Muse account.
From there, the attacker doesn't need to deploy any specific trojan or code to steal data from a user's machine, Wardle explained. They can simply take control of Muse to do so.
As a personal AI agent, Muse is able to help complete tasks and perform actions on a user's computer. This requires that a user give Muse a lot of permissions on their device, more than a user would provide to most other third-party applications. Other popular AI agents like OpenClaw have the same security risks.
Meta predicted the potential security issues with Muse requiring so many system permissions. The company addressed the issue at launch, saying Muse was designed to run on "a dedicated secure computer with its own browser" called Muse Secure VM.
"Personal agents need a new kind of secure computer, so Meta built one for everyone," Meta said. "Muse Secure VM has first-of-its-kind privacy, safety, and security protections engineered into it that no other agent provides."
However, according to Wardle, specific decisions Meta made when creating Muse led to this vulnerability. For example, Wardle shared how Apple keeps all dictation locally on devices for its own applications and transcription features. Meta opted to use the cloud for dictation, which makes the exploit possible, he claimed.
Meta has not yet addressed the zero-day vulnerability. But, they likely will soon. On the same day the exploit was unveiled, Amazon announced that it would be blocking Meta's Muse AI assistant from being able to purchase products for users on its e-commerce site.
