Meta's Muse AI assistant shipped with a serious zero-day vulnerability that allowed any locally installed application to steal a user's Muse account token and weaponize the agent's unusually broad privileges, according to reporting by Ars Technica.

The flaw was discovered by Patrick Wardle, a veteran macOS security researcher, founder of the Objective-See Foundation and a former employee of NASA and the National Security Agency. His disclosure lands at a delicate moment for Meta: roughly 12 hours before Wardle went public, Amazon had already started blocking people from using Muse to shop on its site, calling it an "unauthorized AI agent" that violates Amazon's Conditions of Use. For more context on this story, see our ongoing AI industry coverage.

How the Muse Zero-Day Worked

Muse, which Meta introduced a few weeks ago, is designed to be an aggressive personal assistant. According to Ars Technica, it "books appointments, fills out forms and handles customer service," "proactively takes tasks off your plate," and can "make purchases, generate images, create documents, and connect with your favorite apps and services." The app runs on macOS — there is, curiously, no Windows version — and connects to a user's WhatsApp, email, calendar and social media accounts.

That level of access is what makes the vulnerability significant. For Muse to function, users must authenticate it to each service and grant it sweeping operating system permissions: writing files to disk, accessing the microphone and camera, and monitoring location and calendars.

Wardle found that Meta's developers designed the assistant so that any locally installed app or executed command — regardless of its own macOS permissions — could change a long list of undocumented settings. Most of those settings were innocuous, such as toggling dark mode. One, however, controlled where sensitive user speech is processed, and the same mechanism could expose the token that authenticates a user to their Muse account.

"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars Technica. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself."

In practice, Wardle said he developed several proof-of-concept attacks, including ones that write malicious files to disk. One described attack path involves an attacker's server acting as a proxy between the Muse user and Meta's endpoint: once the user speaks a voice prompt, the attacker's server injects a malicious command — for example, sending an archive of all WhatsApp messages to the attacker — and gains permanent control over the Muse account.

Design Decisions Under the Microscope

Wardle attributed the exploit to several specific design choices. One was Meta's decision to handle Muse dictation in the cloud, where the company can log it, rather than using macOS's long-supported on-device transcription. Had the safer local alternative been chosen, he said, the attack would not have been possible.

Another was allowing any app to control the undocumented settings endpoint. Wardle suggested Meta likely intended for partner apps to adjust interface preferences, but extending that control to where sensitive speech is processed turned a convenience feature into an attack surface.

"To me, the bar is infinitely higher in terms of the security of these apps," Wardle said. "They don't have to be perfect, but when you take a look at Muse, it's like they didn't, in my opinion, think about security, which is really worrisome. At the very least, they should be thinking about security from the very start, and they are just not."

Meta published two posts in as many weeks documenting the security and privacy design decisions behind an assistant with such broad access to user data — a timeline that now reads differently in light of the disclosure. Ars Technica also noted the broader backdrop: revelations that internal testing of models from Anthropic and Google resulted in security breaches of external, third-party networks that engineers never intended to touch.

A Hotfix, and a Warning for Agentic AI

More than 12 hours after the report went live, Meta said it released a hotfix that patched the zero-day. Meta did not immediately respond to a request for comment on the timeline of the fix.

Security experts have long argued that once a device is compromised, all bets are off — a counterargument that vendors of privileged software often lean on. Wardle pushed back on that framing for Muse: a simple variation of the ClickFix social-engineering technique, which has become remarkably effective at tricking people into infecting their own devices, is all an attacker needs to get malicious code running on a target's Mac.

Wardle plans to discuss the vulnerability and other AI assistant threats in more detail at the Objective by the Sea security conference in November.

The episode is a pointed case study in the security debt that agentic AI products can accumulate when they race to market. An assistant that can read your messages, pay for purchases and act across your accounts is, from an attacker's perspective, a single high-value target — and compromising it is far cheaper than building bespoke malware for each service it touches.

For users, the practical lessons are familiar but newly urgent: limit what an AI assistant is allowed to access, treat its privileges as seriously as you treat your own credentials, and be skeptical of products that route sensitive input like voice dictation through third-party servers by default. For the industry, the message from researchers is blunter — security cannot be a post-launch patch for software that holds the keys to someone's digital life.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →