Meta began rolling out its Muse AI assistant with a zero-day vulnerability that let any locally run app or terminal command seize full control of the agent, undercutting founder and CEO Mark Zuckerberg's claim that Muse was "built from the ground up for privacy and security." The flaw was discovered by macOS security expert Patrick Wardle. Meta said it released a hotfix that patched the zero-day more than 12 hours after the initial report went live. Separately, Amazon on Sunday began blocking Muse from its site.
Meta introduced Muse a few weeks ago. The assistant books appointments, fills out forms, handles customer service, makes purchases, generates images, creates documents, and connects with apps and services, and it can create a tool on the fly when a task requires one that doesn't exist. The macOS app, which has no Windows version, works with a user's WhatsApp, email, calendar, and social media accounts. Using it requires giving Muse access to those accounts and to operating system-restricted device resources such as disk writes, the mic and camera, and location and calendar monitoring.
The zero-day let any app or executed code, regardless of its macOS permissions, alter a long list of undocumented settings. Most were innocuous, such as dark mode controls. One let processes change the endpoint where transcription occurs, which is normally a Meta-operated server address. Attackers could redirect that endpoint to their own server and obtain the token granting complete control over the Muse account. Wardle said he built proof-of-concept attacks that wrote malicious files to disk and took pictures, sometimes without alerting the user.
Wardle attributed the exploit to several Meta design decisions. Muse dictation occurs in the cloud, where Meta can log it, rather than through the on-device transcription macOS has long provided; he said the attack would not have been possible under the safer alternative. He also questioned why any app could control the endpoint that processes sensitive user speech, and said the decisions suggested Meta did not consider security from the start. He is the creator of the Objective-See Foundation and a former NASA and National Security Agency employee, and plans to discuss the vulnerability at the Objective by the Sea conference in November.
Amazon told users who tried to shop with Muse that it was an unauthorized AI agent violating Amazon's Conditions of Use. The company said third-party applications that make purchases from other businesses should operate openly and respect service provider decisions about participation, and that it had asked Meta to remove Amazon from the experience. Before the disclosure, Meta published two posts in as many weeks on the design decisions meant to keep the assistant secure and private, following revelations that internal testing of Anthropic and Google models breached external third-party networks.
Wardle said a simple variation of a ClickFix attack was all an attacker needed to take over a Muse account, and he demonstrated sending a prompt to the Meta endpoint through a terminal command. In a statement, Meta said the zero-day was not a remote exploit, and it did not address the ClickFix scenario or explain the use of cloud transcription over the macOS on-device option.
More cybersecurity news from TechManNews.



.jpg)



