- Before a fix, an app running on a Mac could hijack Meta's Muse AI assistant the next time its owner spoke to it.
- The way in was a setting Meta never made public, which picked where your speech became text.
- In one security expert's tests, a hijacked Muse wrote harmful files and took pictures.
- Meta announced a fix after the flaw went public.
Muse is Meta's new AI assistant. Once you give it access, it can use your email, WhatsApp and calendar, plus your Mac's mic and camera. Meta's boss Mark Zuckerberg says it's "built from the ground up for privacy and security." But Mac security expert Patrick Wardle found that any app or command running under your account on the same Mac could set up a takeover.
The way in was a Muse setting Meta never made public, which any app running under your Mac account could change. It picks the server that turns your spoken requests into text, which is normally Meta's. An app could point it at an attacker's server instead. The next time you spoke to Muse, the key that keeps you signed in went there too, and with it came full control of your Muse account.
To show it off, Wardle quietly sent Muse a question from a plain command with no special permissions. The question asked how an attacker like that could be sending it. Muse answered that such a thing wasn't possible, in reply to the attacker's own question. That's an awkward answer to give in the middle of it happening.
In Wardle's tests, a hijacked Muse wrote harmful files and took pictures. Often even a careful user saw no sign of it. After Ars Technica published the report, Meta said it had put out a fix.
Meta also called the bug "not a remote exploit." The attack does need the attacker's code running on your Mac first. Wardle says a simple version of a scam that tricks people into infecting their own computers is enough to get it there.





