Cybersecurity
·By Seedwire Editorial·

Meta’s Muse flaw lets local code take over assistant accounts

Meta’s Muse flaw lets local code take over assistant accounts

Illustration, not documentary evidence of the event.

A reported vulnerability in Meta’s Muse assistant lets locally running code obtain an account authentication token and take control of the agent, according to arstechnica.com. Security researcher Patrick Wardle found that an app or terminal command can redirect Muse’s transcription traffic to an attacker’s server, which then receives the token.

The flaw matters because Muse operates with access users have already granted. The macOS assistant connects to services including WhatsApp, email and calendars, and requests device permissions for tasks such as writing files and accessing the camera. Wardle told the publication that his proof-of-concept attacks could write malicious files and take pictures, sometimes without an obvious indication to the user. Meta did not answer the publication’s emailed questions.

The central security issue is a boundary between ordinary local code and an assistant with extensive permissions. According to the report, local processes can change undocumented Muse settings regardless of their own macOS permissions, including the transcription endpoint. This suggests that treating the attack as merely a consequence of an already compromised device misses the important distinction: code with limited access can acquire the assistant’s broader authority. Wardle also demonstrated a route involving ClickFix, which tricks users into running a command.

For anyone considering connecting sensitive accounts, the concrete question is whether Muse can protect those connections from less privileged software on the same machine. The report describes account takeover and proof-of-concept attacks, but does not establish exploitation in the wild or provide a confirmed fix. A meaningful response would need to address both who can modify sensitive settings and how authentication tokens are protected when an endpoint changes. A general assurance about privacy would not resolve those specific questions.

Muse’s usefulness also depends on services accepting its actions. Amazon began blocking the assistant before Wardle’s disclosure and said it had asked Meta to remove Amazon from the experience. The report does not establish that the block was a response to the flaw. For teams evaluating purchasing agents, that creates a separate dependency: granting an assistant permission to shop does not ensure the retailer will let it complete the transaction.

Meta Muse
macOS security
AI assistants
account takeover
ClickFix
agent permissions
Seedwire Newsletter

Follow Seedwire by email

Request Seedwire news emails. There is no guaranteed delivery schedule. You can withdraw your request through the privacy contact.

By selecting Subscribe, you request Seedwire news emails. Privacy and withdrawal.