Meta pushed a hotfix for its Muse assistant this week after a researcher showed that a short terminal command could hand an attacker full control of the agent. The flaw lived in an undocumented setting inside the macOS app.
Patrick Wardle, who runs the Objective-See Foundation, found that any locally installed program, whatever permissions macOS had granted it, could rewrite a list of hidden Muse preferences. Most were harmless. One pointed the app’s transcription traffic at a different endpoint.
That was enough. By inserting their own server between Muse and Meta, attackers could add a command to a spoken prompt, and the account token would follow the audio to the same address. Wardle built proof-of-concept attacks that wrote files to disk and took photos without alerting the user.
Meta’s David Singleton called it a local privilege escalation rather than a remote exploit, noting that harm required malicious code already running under the user’s account. The company shipped the fix within a day of Ars Technica’s report.
The timing is awkward. Amazon had already blocked Muse from shopping on its site, and the disclosure undercut the privacy-first framing Meta used when it launched the agent this month. Muse downloads still outpaced ChatGPT’s first 12 days in the US and Canada.