Vulnerability discovered in Meta's Muse AI assistant
Quick Look
- The vulnerability in Meta's Muse artificial intelligence assistant, discovered by Patrick Wardle, allowed malware to capture authentication information and take action on behalf of the user.
- Following the announcement, Meta released an urgent update for the macOS application.
AI-generated summary
Why It Matters
Meta's artificial intelligence assistant called Muse is an artificial intelligence agent with capabilities such as sending e-mails, shopping and performing transactions on behalf of the user.
Muse, Meta's personal artificial intelligence assistant that can send e-mails, shop and perform transactions on behalf of the user, has come to the fore with a serious security vulnerability.
The vulnerability, discovered by Patrick Wardle, who works on macOS security, allowed malware running on the computer to capture Muse's authentication information and direct the artificial intelligence agent to the user's name.
In the proof attacks prepared by Wardle, it was stated that Muse could be used to take photos and add harmful files to the computer without a clear warning to the user. Meta released an emergency fix for the macOS app after the vulnerability was made public.
FOUND IN OPEN VOICE WRITING SYSTEM
The root of the security problem is that Muse sends voice commands to Meta's servers instead of processing them on the Mac.
There was a development setting within the application, which was not shown to the user, that determined the server to which voice recordings and transcripts would be sent. This setting normally pointed to the server belonging to Meta.
However, any application or terminal command running under the user account logged in to the computer could change this address without obtaining additional macOS permission.
When the attacker directed the setting to the server under his control, the voice commands given by the user to Muse could first be sent to the attacker. More importantly, during this process, it became possible to capture the authentication key used to control the Muse account.
By capturing the authentication key, the attacker could take advantage of the permissions previously granted to Muse instead of requesting new permissions. Thus, the operations performed could appear as if they were coming from the reliable Muse application in terms of the operating system.
In his statement, Meta emphasized that this is not an independent attack that can be carried out remotely and that it requires malicious code to be run on the computer beforehand.
URGENT UPDATE FROM META
Patrick Wardle publicly disclosed the vulnerability and the attack example he prepared. Meta sent an emergency fix to the macOS app after the news was published.
The company argued that the risk was limited, stating that in order for the security bug to be used in real life, malicious code must already be present on the user's device. Despite this, the update that prevented the misuse of the hidden server setting was released in a short time.
What to Watch
AI outlook — possibilities, not facts
Meta will roll out security updates for other operating systems as well
Likely · Within weeks
Open Questions
- How many users could be affected by this vulnerability?
- How long has the gap existed?
- What will Meta do to prevent similar vulnerabilities?







