- Mac security researcher Patrick Wardle found a bug that let any Mac app take over Meta's new Muse AI assistant.
- An attacker who took over Meta's Muse assistant could use the email, WhatsApp, microphone and camera access people had given it.
- Patrick Wardle's test attacks used Meta's Muse to take pictures and save harmful files on a Mac, often with no sign to the person.
- Patrick Wardle's notes say the Muse attack needs the attacker's program or command already running on the person's Mac.
- Ars Technica reported the Muse bug on September 21, and Meta said on September 22 that it had released a fix.
Patrick Wardle, a Mac security researcher, found a serious bug in the Mac app for Muse, Meta's new AI assistant. The bug let any app on the Mac, or even one typed command, take over Muse and everything people had let it reach. Ars Technica, a tech news site, reported the bug on September 21. Meta said on September 22 that it had released a fix.
Ars Technica Muse zero-day report
Meta says Muse books appointments, fills out forms and makes purchases for people. Muse can work with the WhatsApp, email, calendar and social media accounts people choose to connect. Macs ask permission before an app uses the microphone, camera, location or protected files. Muse can use them once people allow it, and the bug let other apps without that permission use them through Muse.
When someone speaks to Muse, the app sends their voice to a Meta computer that turns it into text. Muse has a setting, never documented by Meta, that decides which computer gets the voice. Any Mac app could change that setting to point at an attacker's computer instead. The attacker could then get the person's spoken requests and the login code that keeps them signed in to Muse.
With that login code, the attacker has full control of the person's Muse account. Ars Technica says the attacker's computer can pass each request on to Meta and add extra orders for Muse. If WhatsApp is connected, those orders could make Muse send all the person's WhatsApp messages to the attacker. Wardle's test attacks took pictures and saved harmful files, often with no sign to the person.
Wardle's notes say the attack only works if an attacker can already run a program or command on the person's Mac. But Wardle says a scam called ClickFix, which tricks people into running an attacker's command on their own computer, is enough to do that. Meta's statement said the bug was "not a remote exploit."
Wardle's not-a-mused proof of concept
Wardle says that in his opinion, Meta didn't seem to think about security when it built Muse, which he called "really worrisome." Ars Technica says Macs have a built-in way to turn speech into text without the voice leaving the Mac. The attack wouldn't have worked if Muse used it. Meta hasn't explained why it chose to send people's voices to its own servers instead.



