Skip to content

News with true faith

Technology

Meta fixes security vulnerability in Muse Mac AI assistant

Meta has issued an emergency security patch for its Muse artificial intelligence assistant on Mac after a vulnerability exposed WhatsApp user messages.

Meta fixes security vulnerability in Muse Mac AI assistant

Meta has released an urgent security update to fix a zero day vulnerability in its Muse artificial intelligence assistant for Mac computers, the tech giant confirmed.

The patch was deployed hours after cybersecurity publication Ars Technica reported the flaw, following disclosure by security researcher Patrick Wardle, according to reporting by technology outlet The Verge.

The vulnerability enabled local software to hijack the AI assistant, granting unauthorized access to private user data, including personal WhatsApp messages.

Meta, the parent company of Facebook and Instagram, introduced Muse earlier this month as an integrated digital assistant capable of making online purchases, scheduling calendar appointments, and managing user communication channels.

To execute those tasks, the Mac application demands broad permissions across macOS, Apple's desktop operating system, including access to local file storage, system cameras, and microphones.

Exploiting Voice Transcription Settings

The security flaw stemmed from how Muse managed internal system settings on macOS.

Any local application or command line prompt running on the computer could alter Muse configuration files without requiring elevated user permissions.

One editable setting specified the remote server address responsible for transcribing spoken user voice commands.

If an attacker modified that address to point to a malicious server, Muse transmitted its secret digital authentication token whenever the user dictated a command.

An authentication token serves as a digital credential that verifies user identity to cloud services without requiring password entry for individual transactions.

Once an attacker captured the authentication token, their server could issue automated commands forcing Muse to package and upload confidential WhatsApp conversation logs stored on the device.

Data Theft and Silent Surveillance

Wardle explained to technology journalists that attackers could manipulate the AI assistant to exploit its pre-existing privileges for arbitrary tasks.

He noted that malicious actors no longer needed to write sophisticated custom malware for Mac systems when they could simply commandeer Meta's own software.

The researcher criticized Meta for sending audio dictation to external cloud servers, pointing out that macOS includes built in local speech recognition tools that would have eliminated the network vulnerability entirely.

Wardle also questioned why unprivileged third party applications were allowed to alter sensitive operational parameters within the Muse application architecture.

During security testing, Wardle demonstrated that exploiting the vulnerability allowed writing malicious files to disk and taking photos using the built in computer camera without triggering user alerts.

Wardle stated that security standards for software operating with broad system access demand strict scrutiny.

He observed that while software is rarely flawless, Muse appeared to be released without basic security considerations, describing the lapse as deeply troubling for consumer privacy.

Terminal Exploits and Social Engineering

Exploiting the zero day flaw required executing code on the victim computer, which attackers could trigger through social engineering tactics.

Wardle verified that a malicious technique called ClickFix could be adapted to gain full control of the Muse application.

ClickFix attacks use deceptive web pages displaying fake software errors or security verifications that prompt users to copy and execute malicious terminal scripts disguised as technical fixes.

Prior to the patch release, Wardle posted a public warning on social media platform X on September 21, 2026, advising users against installing Muse due to the ease with which it could be turned into a backdoor.

Meta Defense and Amazon E-Commerce Blocks

David Singleton, an executive at Meta Superintelligence Labs, defended the company's software design following the public disclosure.

Singleton argued that the real world security risk remained low because an attack required malicious code to already be running on the user's computer.

However, he acknowledged that the vulnerability permitted existing malware to expand its reach by co-opting permissions previously granted to Muse.

The security incident follows recent promotional statements by Meta Chief Executive Officer Mark Zuckerberg, who had claimed that Muse was engineered from the ground up to protect user privacy and data security.

Separately, e-commerce giant Amazon acted to restrict Muse functionality roughly 12 hours before Wardle publicly disclosed the security flaw on September 21, 2026.

Amazon began blocking transactions attempted through the assistant, asserting that Muse violated company terms of service.

The retailer requested that Meta disable automated shopping features for Amazon customers through Muse, maintaining that online merchants retain full authority over whether automated AI agents are permitted to operate on their commerce platforms.

Related

Leave a comment

Your email address will not be published. Required fields are marked *