Skip to content

Product1 publisher2 min readPublished

A single undocumented setting let any Mac app take over Meta's Muse agent

Patrick Wardle found that any locally installed app could repoint Muse's transcription endpoint and collect the token to an account already holding microphone, camera and disk permissions. Meta said it shipped a hotfix.

The Product Desk · Product desk

Photograph accompanying A single undocumented setting let any Mac app take over Meta's Muse agent
Photo: gizmodo.com

What happened

  • Meta introduced Muse a few weeks ago as a macOS app with no Windows version, and it works with a user's WhatsApp, email, calendar and social media accounts.
  • A zero-day in the assistant let any locally installed app or terminal command reach the token that authenticates a user to their Muse account.
  • Wardle said he built proof-of-concept attacks on the flaw that wrote malicious files to disk and snapped pictures, in many cases with no indication to even an alert user.
  • Meta said it released a hotfix patching the zero-day more than 12 hours after the post describing it went live.
  • Amazon began blocking Muse from its site on Sunday.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • exposure Whoever hijacks the agent inherits the microphone, camera, disk and calendar access the user granted it, so the assistant stands in for the Mac malware an attacker would otherwise have to write.
  • decision macOS grants these permissions per app, not per task. The rollout choice is binary: approve the agent with all five resource classes, or keep it off the machine.
  • constraint As long as Amazon keeps the block in place, the shopping errands Meta advertises will not complete at that retailer, whatever the agent is able to do elsewhere.
  • contradiction Zuckerberg's claim that Muse was built from the ground up for privacy and security is the pitch a buyer weighs against a flaw that needed no granted permission at all.

Installing Muse is a permissions exercise before it is anything else. The user authenticates the app to each service, then approves macOS prompts covering five classes of protected resource: disk writes, the microphone, the camera, location and calendars [6][1]. Apple spent years building those prompts to keep installed apps and terminal commands away from exactly those resources, and Wired's assessment is that Muse undoes the defaults [7].

The flaw sat underneath all of that. Meta let any locally installed app or executed code change a long list of undocumented Muse settings, whatever macOS permissions that code held, and most of the settings are dull, like dark mode [9]. One of them set the endpoint where dictation is transcribed, normally a server Meta runs. A process that repointed it at an attacker's server would receive the token that gives complete control of the Muse account [10]. The attacker needed only code running as the user [2].

"We can manipulate the agent and leverage its privileges to do whatever we want," said Patrick Wardle, the macOS security expert who found the flaw and spoke to Ars before the hotfix [11][13]. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself," he said [12].

The dictation choice made the difference, Wardle said: Muse transcribes in the cloud, where Meta can log it. macOS has long offered apps a way to transcribe on the device, and the safer path would have closed the attack [17]. Meta has published two posts in as many weeks documenting the design decisions behind the assistant's security and privacy [16].

Wired does not report Amazon's reason for the block [19]. Meta advertises Muse as able to make purchases, fill out forms and connect with a user's favourite apps and services [5].

For whoever has to approve this on managed Macs, two checks are worth more than a vendor security post. The first is whether, for every OS permission the agent requests, the platform offers an on-device path the vendor skipped, and what the vendor gained by skipping it; cloud transcription is the case in point here [17]. The second is whether the build's settings can be written from a shell with nothing granted. A shell with no permissions is how the Muse token leaked [9][10]. "To me, the bar is infinitely higher in terms of the security of these apps," Wardle said [20].

What to watch

  • Whether Amazon states a reason for the block, or extends it to other agentic assistants reaching its site.
  • Whether Meta's hotfix restricts every undocumented setting to privileged callers or only the transcription endpoint.
  • Whether a Windows build follows, since Muse ships only for macOS today.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories