Muse Mac App Security Flaw Allows Hackers to Exploit the AI Agent

Meta has deployed an emergency hotfix for its Muse macOS desktop app following the public disclosure of a significant security flaw, that allowed attackers to manipulate the AI agent and gain access to user accounts.

The zero-day vulnerability, discovered by prominent macOS security researcher Patrick Wardle, demonstrated how local applications could hijack the AI assistant’s transcription framework. Addressing the findings directly on social media, David Singleton of Meta Superintelligence Labs confirmed that the engineering team moved quickly to issue a patch.

We appreciate this report and have issued a hotfix to the app to address the issue,” Singleton wrote on X. He went on to defend the safety profile of the desktop assistant, emphasizing the specific conditions needed for the exploit to execute.

“This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low. Nonetheless, we have issued a hotfix to the app to address the issue.”

The underlying vulnerability centered around how the Muse app handled its dictation and audio processing parameters. Wardle discovered that an undocumented internal setting controlling the app’s dictation endpoint was left unprotected. By manipulating this hidden configuration option, local code running on a user’s Mac could trick Muse into redirecting its transcription requests away from official Meta servers and toward an attacker’s server.

To resolve the security hole, Meta’s engineers stripped out the vulnerable setting entirely, blocking local software from altering where dictation audio and requests are sent.

While Singleton pushed back on the severity by framing the issue as a local attack rather than a remote breach over the open web, security experts caution against taking local privilege escalation bugs lightly. Once malicious code lands on a computer, an agentic AI tool with wide system permissions becomes an attractive target to turn a minor breach into total account access.

Want to see more of our stories on Google?

Add iPhone in Canada as a Preferred Source on Google

P.S. Want to keep this site truly independent? Support us by buying us a beer, treating us to a coffee, or shopping through Amazon here. Links in this post are affiliate links, so we earn a tiny commission at no charge to you. Thanks for supporting independent Canadian media!

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x