NewsTradingSentimentEventsCommunityBriefing
Tech

Meta AI Assistant Muse Suffers Critical Zero-Day Flaw

By Tech Desk · · 3 min read
A flat vector illustration of a computer terminal window with a security shield symbol.
Illustration: Tradingbird, based on a photo published by Ars Technica

A zero-day vulnerability allows local apps to hijack Meta's Muse assistant, undermining its privacy claims and leading Amazon to block the service.

Key points

  • A zero-day flaw allows local apps to hijack the authentication token of Meta's Muse assistant.
  • Amazon blocked Muse from its site due to the security risk posed by the vulnerability.
  • The assistant requires broad macOS permissions, bypassing default OS security defenses.

Meta’s new AI assistant, Muse, is facing a severe security setback that contradicts the company’s initial marketing. Mark Zuckerberg promoted the tool as being built from the ground up with privacy and security in mind, yet a discovered zero-day vulnerability gives locally running applications complete control over the agent. The flaw is so significant that Amazon began blocking Muse from accessing its site on Sunday, highlighting the immediate risk to users who granted the assistant broad permissions.

The assistant was introduced just weeks ago with promises to handle complex tasks like booking appointments, filling out forms, and making purchases. It integrates deeply with a user’s digital life by connecting to WhatsApp, email, calendars, and social media accounts. To perform these actions, Muse requires extensive access to macOS resources, including the microphone, camera, and file system, effectively bypassing the operating system’s default security defenses that Apple has spent years hardening to protect user data.

Local apps can hijack authentication tokens

The core of the vulnerability lies in how Muse manages authentication. Developers designed the system so that any locally installed app or executed code, regardless of its macOS permissions, can modify a list of undocumented settings. While most of these settings are harmless, such as controlling dark mode, one critical setting allows processes to change the endpoint where transcription occurs. This change redirects data to an attacker-controlled server, which then captures the token required for full control of the Muse account.

This mechanism allows malicious software to bypass the strict sandboxing measures that macOS enforces on third-party applications. By altering the transcription endpoint, attackers gain unauthorized access to the secure token that authenticates users to their Muse accounts. This means that even a simple command entered into a terminal can potentially strip a user of their agent's integrity, exposing their connected services to compromise without their knowledge.

Privacy promises clash with technical reality

Ars Technica reports that the situation raises serious doubts about Meta’s security claims. The assistant creates new tools on the fly when necessary, a feature that adds flexibility but also expands the potential attack surface. For Muse to function, users must grant it access to sensitive device resources, a trade-off that Meta presents as essential for utility but which the zero-day flaw reveals as a significant security risk. The disconnect between the advertised privacy protections and the underlying code behavior is now under scrutiny.

The immediate reaction from major platforms underscores the severity of the issue. Amazon’s decision to block the assistant is a practical acknowledgment that the current implementation poses a threat to transaction security. Users who have installed the macOS version of Muse are advised to review their permissions and be aware that the tool’s ability to act on their behalf can be exploited by local software. This incident serves as a cautionary tale about the risks of granting AI assistants deep operating system-level access.

Trade-offs of deep system integration

The Muse controversy highlights the inherent tension between convenience and security in AI assistants. To be useful, the agent must interact with the operating system and user accounts at a deep level, which inherently reduces the isolation that protects against malicious code. The lack of a Windows version suggests that Meta may be testing the waters with macOS, but the zero-day flaw indicates that the current architecture is not robust enough to handle the threat model of a modern desktop environment.

As Meta works to patch this vulnerability, users must weigh the benefits of automated task management against the potential for account takeover. The incident demonstrates that even when a company emphasizes security in its messaging, the technical implementation may still contain critical gaps. For now, the safest approach is to limit the permissions granted to such assistants and to monitor any unusual activity in connected accounts.

Based on reporting by Ars Technica, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories