Inside Wired
en

Meta Patches Zero-Day Vulnerability in Muse That Allowed Misappropriation of Its AI Agent

Meta Patches Zero-Day Vulnerability in Muse That Allowed Misappropriation of Its AI Agent
AI-generated image

Description

Meta has deployed an emergency patch for a zero-day vulnerability discovered in the Muse macOS application. The flaw allowed pre-installed software on the Mac to redirect the assistant’s communications, intercept its authentication data, and ultimately exploit the numerous permissions granted to the agent. This incident illustrates a new risk associated with autonomous assistants: the more privileges and connections they possess to personal services, the greater the potential consequences of their compromise.

Discovery of the Vulnerability

The vulnerability was discovered by Patrick Wardle, a researcher specializing in macOS security and founder of Objective-See. His analysis showed that Muse exposes an internal setting allowing modification of the address used for processing transcription requests. A local, non-privileged process could change this destination, redirecting communications to a server controlled by an attacker.

This weakness notably allowed intercepting dictated queries sent to Muse and injecting new instructions before they reached Meta’s servers. More concerningly, the mechanism could expose the authentication token associated with the Muse account. Ars Technica reports that Wardle developed several demonstrations allowing for subsequent agent misuse, such as writing files or taking photos without visible user warning.

Scope of Potential Impact

The potential impact primarily stems from the privileges required for Muse's operation. The assistant can be connected to messages, emails, calendars, and various services utilized by its owner. Once compromised, an attacker could therefore seek to exploit the access the user voluntarily granted, rather than having to separately develop malicious tools for each individual service. Wardle precisely describes this scenario as one of the main risks associated with this new category of personal assistants.

It is important to note that the flaw did not allow a remote attacker to directly take control of a Mac over the internet. Meta specified that exploitation required malicious code to already be executed under the user's account on the machine. David Singleton, an employee at Meta Superintelligence Labs, described the problem as a local attack and estimates that this condition severely limits the practical risk for users. Nevertheless, Meta quickly published a patch for the Muse application on Mac.

However, Wardle considers this prerequisite insufficient to minimize the problem. He notably demonstrated that a ClickFix-style attack, where a victim is induced to execute a local command, could provide the necessary starting point. Once this step was cleared, the attacker could use Muse and its permissions as a relay for accessing the data and services to which the assistant had access.

Architectural Challenges of AI Agents

This incident comes at a time when Meta has heavily emphasized security and privacy in the design of Muse. The discovered problem does not invalidate the entire architecture by itself, but rather reveals a specific difficulty regarding agents capable of acting directly on their users' devices and accounts. Their security depends not only on the AI model and its remote environment, but also on every local interface that allows control over the agent.

The discovery also arrives during a period of exceptional attention surrounding Muse. Launched just weeks ago, the assistant has seen rapid adoption, while Amazon recently blocked its use for making purchases on its platform. While these events concern different issues, they place the permissions, transparency, and control of autonomous agents at the center of the debate surrounding their deployment.

Ultimately, the vulnerability in Muse demonstrates why AI agent security cannot be evaluated the same way as a simple chatbot. An assistant capable of manipulating files, accessing communications, or interacting with external services becomes a new layer of privilege on the device. The more autonomy this layer gains, the more the mechanisms designed to control it must be protected against local applications and processes attempting to divert its capabilities.

While the rapid correction of the flaw limits immediate risk, the episode highlights a more enduring challenge for personal agents: their capabilities are also becoming an attack surface. The security of these assistants will now have to evolve at the same pace as the privileges they are granted.

Translated from French with AI

More you may want to explore.

More you may want to explore.

More you may want to explore.