
Meta's Muse AI Agent Bypasses Apple's Security Layer in New Attack
Key takeaways
- Zero-day allows any local app to steal Muse's authentication token via transcription endpoint manipulation
- Vulnerability bypasses Apple's macOS security model that normally restricts app and terminal access
- Amazon blocked Muse; Meta has not publicly commented on the flaw or timeline for a fix
Muse, Meta's newly launched AI assistant for macOS, contains a critical zero-day vulnerability that lets attackers gain complete control over the agent and its privileges. Security researcher Patrick Wardle found that any app or command running on a user's computer can intercept Muse's authentication token by manipulating undocumented settings—specifically by changing where the assistant sends audio transcription. Wardle demonstrated proof-of-concept attacks that write malicious files and capture photos with minimal user indication.
Muse is designed to book appointments, fill forms, make purchases, and integrate with WhatsApp, email, calendars, and other services. To function, users must grant it broad macOS permissions that Apple normally restricts to prevent unauthorized access. Meta's design choice to handle transcription in the cloud, rather than locally, creates the exploitable endpoint. Amazon began blocking Muse from its platform on Sunday, signaling industry concern. Meta declined to comment on the vulnerability.
The bigger picture
This discovery undermines Meta's recent security messaging around Muse, which Zuckerberg publicly positioned as 'built from the ground up for privacy and security.' The flaw highlights a recurring tension in AI assistants: granting broad system access enables powerful functionality but dramatically expands the attack surface. Other AI platforms like Claude and ChatGPT plugins face similar design pressures. Regulatory scrutiny over AI safety will likely intensify, especially as agents gain control over sensitive accounts and devices.
We're covering this because it exposes a real gap between AI safety claims and implementation—one that affects everyday users, not just enterprises. Wardle's discovery matters beyond the security community; it shows how privilege escalation in AI tools can quietly bypass decades of OS-level protections. We'll be watching how Meta responds and whether other assistants face similar audits.
As an Amazon Associate, LagPing earns from qualifying purchases. Product links are affiliate links.
You might also like

Founders Must Rethink Hiring as AI Agents Become Core Team Members
6d ago

Autonomous AI Agents Flooded Ruby Package Repository With Malicious Code
Sep 13

Anthropic Settlement Chaos: Publishers, Agents Stake Claims on Author Payouts
Sep 7

Claude Opus 4.6 Bypasses Its Own Content Rules With a Simple Persuasion Trick
Aug 22