Monday, 21 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 22 September 2026 at 01:45

Meta's AI assistant Muse found to have serious security flaw

A security researcher has discovered a critical vulnerability in Meta's AI assistant Muse that lets any local app or terminal command hijack a user's account. Amazon has already begun blocking Muse from its site.

Foto: Ars Technica

Meta CEO Mark Zuckerberg has promoted the company's new AI assistant Muse as being built from the ground up for privacy and security. But a serious vulnerability discovered by macOS security researcher Patrick Wardle casts doubt on those claims.

Launched a few weeks ago, Muse can book appointments, fill out forms, make purchases, generate images and documents, and connect to a user's WhatsApp, email, calendar and social media accounts. To function, it requires broad access to macOS-protected resources such as file writing, the microphone, camera and location.

How the exploit works

Wardle found that any locally installed app or executed terminal command can alter a long list of undocumented Muse settings, regardless of the macOS permissions it was granted. One of these settings controls the server endpoint where voice transcription is processed. Normally this points to a Meta-operated server, but an attacker can redirect it to their own endpoint, capturing the authentication token that grants full control over the victim's Muse account.

Wardle said he built several proof-of-concept attacks that can write malicious files to disk or take photos without any visible sign to the user. He noted that a simple variant of a so-called ClickFix attack is enough to fully hijack a Muse account.

Meta stays silent, Amazon acts

Meta did not respond to questions about the vulnerability. The company has published two blog posts in recent weeks describing the security design behind Muse. About 12 hours before the flaw was disclosed publicly, Amazon began blocking Muse from making purchases on its site, stating that it constitutes an unauthorized AI agent violating its terms of use.

Wardle, founder of the Objective-See Foundation and author of a book series on Mac malware, plans to discuss the vulnerability in more detail at a security conference in November.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category