Muse is Meta’s new AI assistant for macOS that can manage calendars, email, WhatsApp, make purchases, generate content, and create on-the-fly tools, but it requires broad permissions to user accounts and device resources. A zero-day discovered by macOS researcher Patrick Wardle lets any locally installed app or terminal command change Muse’s undocumented settings - most dangerously the transcription endpoint - and redirect speech processing to an attacker-controlled server. That redirection causes Muse to send the account authentication token to the attacker, giving complete control of the Muse account; Wardle demonstrated proof-of-concept attacks that write files, capture images, and exfiltrate WhatsApp content with little or no user indication.
The vulnerability is rooted in two design choices: heavy reliance on cloud-based dictation instead of on-device processing and allowing any local process to modify sensitive undocumented settings, effectively undoing macOS permission protections. A simple ClickFix-style interaction or terminal command is sufficient to exploit it. Meta has posted about Muse’s security but did not respond to questions about the flaw, and Amazon has already blocked Muse from shopping on its site. The combination of extraordinary privileges and these engineering decisions makes Muse untrustworthy in its current form and raises urgent security and privacy concerns.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.