Meta Muse flaw could let Mac malware use the AI agent’s access

Days after Meta brought Muse to Mac, security researcher Patrick Wardle disclosed a flaw that could let malware already running on the computer control the AI assistant through access the user has given it.

Meta says Muse can handle tasks such as filling out forms, booking travel and making purchases. The Mac app can also work with files, messages, email, calendars and connected accounts. Users choose what Muse can access, so the potential reach of an attack depends on the permissions and accounts they have linked to the assistant.

Wardle found the weakness in Muse’s voice-dictation feature. A program running on the Mac can change where Muse sends dictated requests, directing them to a server controlled by an attacker. When the user next speaks to Muse, that server could receive the request and the token that authenticates the Muse account. It could also add instructions for the assistant to carry out using the access Muse already has.

Wardle told Ars Technica that he built demonstrations in which Muse wrote files and took photos. His concern is that malicious code with limited permissions could use the assistant to reach files, device features or connected services that the code could not access on its own.

An attacker would first have to get code running on the user’s Mac. Wardle’s tests show what the flaw can do, but there are no reported cases of it being used against Muse users. Meta did not answer Ars Technica’s questions about the finding.