Meta has released a security patch for its Muse macOS application after the discovery of a zero-day vulnerability that enabled attackers to take control of the AI agent. The flaw, identified by security researcher Patrick Wardle, allowed for the potential hijacking of user accounts through local code execution.

What Happened

The vulnerability relied on an undocumented setting within the Muse app that permitted local code to redirect transcription processing. Instead of data being sent to Meta’s servers, the exploit allowed attackers to route it to their own endpoints. This redirection effectively granted the attacker access to the victim's Muse account. The bug required local access to the user’s device to be exploited.

Why It Matters

Several architectural decisions contributed to the flaw, specifically the choice to process Muse dictation in the cloud rather than on-device, and the permission structure that allowed any application to modify Muse’s undocumented settings. This incident highlights the security risks associated with cloud-dependent AI agents and the potential for local processes to interfere with remote data streams if access controls are not strictly enforced.

The Bottom Line

Meta has addressed the issue with a patch, mitigating the risk for Muse users on macOS. The incident serves as a reminder for developers of AI agents to scrutinize local-to-cloud data pathways and restrict access to configuration settings.