A significant security flaw has been identified in Meta’s Muse AI agent for macOS, posing a risk for malware to hijack the assistant. This zero-day vulnerability allows malicious software, operating under a user’s account, to intercept prompts, inject harmful instructions, and extract authentication details.
Security Implications of the Vulnerability
The vulnerability is particularly alarming due to the potential for a compromised agent to inherit the user’s wide-ranging permissions. These permissions include access to numerous connected services that users trust Muse with. Security expert Patrick Wardle, of Objective-See, brought this issue to light, offering a proof-of-concept exploit dubbed ‘not-a-mused’. His research highlights that Muse’s configuration setting, endo_voyager_dictation_endpoint, can be altered by a local process without needing elevated permissions, redirecting Muse’s dictation traffic to an attacker-controlled server.
Once redirected, attackers can capture and manipulate the audio and prompts intended for Muse, enabling them to execute unauthorized commands or content through a seemingly trusted AI workflow.
Potential for Exploitation
While the vulnerability does not allow remote code execution on a clean Mac, attackers must first run code as the local user, possibly through traditional malware or social engineering. Wardle emphasizes that this flaw amplifies access, allowing standard malware to exploit Muse’s extensive authority granted by macOS privacy controls.
Muse’s capabilities are extensive, allowing it to interact with files, applications, and more, raising concerns about the power it holds. An attacker in control of Muse could misuse these connected resources, highlighting the risks of trusted AI agents becoming single points of failure.
Concerns and Recommendations
Wardle’s proof-of-concept demonstrates only a fraction of Muse’s 50+ commands. Other demonstrations have shown compromised accounts discovering linked devices and initiating scans, extending the threat beyond the initial target. The disclosure has sparked significant concerns within the cybersecurity community, with experts warning about the difficulty in distinguishing legitimate user actions from those initiated by an attacker using a trusted application.
Meta promotes Muse as a security-focused personal agent, emphasizing its secure virtual machine and protected credential storage. Despite this, the company had not addressed Wardle’s findings publicly at the time of reporting. Until a verified solution is available, users are advised to treat Muse as a high-risk target, reviewing permissions, rotating credentials, and monitoring for unusual activity.
Organizations should limit the use of unapproved AI agents on managed Macs and scrutinize any modifications to Muse’s endpoint settings to mitigate risks.
