- A bug in Meta's Muse Mac app could let hackers take over the AI assistant.
- Hackers could then reach anything Muse could, like email and the camera.
- The attack needs a hacker's program or command already running on the Mac.
- Meta says it has released a fix for the bug.
Mac security expert Patrick Wardle found a bug in the Mac app for Muse, Meta's new AI assistant. A hacker's program already on your Mac could use the bug to take over Muse the next time you spoke to it. The hacker could then reach anything you'd let Muse use, like your email, WhatsApp, mic or camera. The bug went public September 21, and Meta said the next day it had released a fix.
Ars Technica Muse zero-day report
Meta says Muse can book appointments, fill out forms and make purchases for you. It can work with your email, calendar and WhatsApp if you connect those accounts. On a Mac, you can also let Muse use the microphone, camera, location and protected files, which Macs make apps ask permission for. Meta's CEO, Mark Zuckerberg, has said Muse is "built from the ground up for privacy and security."
When you speak a request to Muse, the Mac app sends your voice to a Meta server that turns it into text. Before the fix, a hidden Muse setting chose which server that was. Wardle found that any program running in your Mac account could change it without special permission. So a hacker's program could send your voice to the hacker's own server instead.
The next time you spoke to Muse, your request went to the hacker's server along with Muse's login token. A login token is what keeps you signed in, so whoever has a copy can use your Muse account as you. The hacker's server could also add its own orders to your request, like sending all your WhatsApp messages to the hacker.
Meta says the bug was "not a remote exploit," meaning a hacker can't use it over the internet alone. The attack only works if a hacker's program or command is already running on your Mac. But Wardle says a ClickFix scam could trick you into running the hacker's command yourself. ClickFix scams trick people into running commands that infect their own computers.
Wardle's not-a-mused proof of concept
Wardle built several working attacks. In them, the hijacked Muse saved harmful files on the Mac and took pictures, often with no sign even to someone paying close attention. He says the attack wouldn't have worked if Muse turned speech into text on the Mac itself, which Macs can already do.





