ByteBulletin

[research] · · 3 min read

Meta Muse zero-day exposes agent token to local apps

A vulnerability in Meta's new AI assistant allows any local macOS command to hijack the agent's authentication token, undermining its privacy claims and prompting Amazon to block the service.

By ByteBulletin Editor · Editor

Meta Muse zero-day exposes agent token to local apps

AI-generated illustration · Z-Image-Turbo, self-hosted


Meta's new AI assistant, Muse, has a serious security flaw that allows any locally installed app or terminal command to gain complete control of the user's account. According to Ars Technica, the zero-day vulnerability was discovered by Patrick Wardle, a macOS security expert and creator of the Objective-See Foundation. The exploit works by allowing unprivileged processes to change an undocumented setting that redirects the endpoint where voice transcription occurs. Once an attacker redirects this endpoint to their own server, they can intercept the authentication token that grants full control over the Muse agent, including its access to WhatsApp, email, and calendar data.

The vulnerability is particularly concerning because it bypasses macOS security controls that Apple has spent years developing to prevent apps from accessing sensitive resources like the microphone, camera, and file system. Muse requires broad permissions to function, including writing files to disk and monitoring location, but the zero-day allows attackers to leverage these permissions without the user's explicit consent. Wardle demonstrated that a simple terminal command can be used to send a malicious prompt to the Muse endpoint, resulting in the agent performing actions like writing malicious files to disk or sending an archive of WhatsApp messages to the attacker.

The Technical Flaw

The core of the vulnerability lies in Muse's design decision to allow any locally installed app to control a list of undocumented settings. Most of these settings are innocuous, such as controlling dark mode, but one critical setting allows processes to change the endpoint where transcription occurs. Normally, this endpoint is a server address operated by Meta, but an attacker can change it to their own endpoint. Once this happens, the attacker can intercept the authentication token that gives complete control over the Muse account.

Wardle explained, "We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself." He developed several proof-of-concept attacks that demonstrate the vulnerability, including writing malicious files to disk and snapping pictures, often without any indication to the user.

Meta's Response and Amazon's Block

Meta has not responded to questions about the vulnerability, but the company has published two posts in the past two weeks documenting the design decisions that went into ensuring Muse's security and privacy. These posts come amid revelations that internal testing of models from Anthropic and Google has resulted in security breaches of external, third-party networks, raising questions about the security practices of AI developers.

Amazon, meanwhile, began blocking Muse from its site on Sunday, citing violations of its Conditions of Use. The company stated, "We think it's fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate." Amazon requested that Meta remove Amazon from the Muse experience, highlighting the broader concerns about the security and privacy of AI agents that can make purchases on behalf of users.

Implications for Developers and Users

The Muse zero-day raises serious questions about the security and privacy of AI assistants that require broad access to user data and resources. Developers building similar tools must consider the security implications of allowing local apps to control sensitive settings and endpoints. Users should be cautious about granting such broad permissions to AI assistants, especially those that can make purchases or access sensitive data like WhatsApp messages and email.

Wardle emphasized the need for higher security standards in AI assistant development, stating, "To me, the bar is infinitely higher in terms of the security of these apps. They don't have to be perfect, but when you take a look at Muse, it's like they didn't, in my opinion, think about security, which is really worrisome." He plans to discuss the vulnerability and other AI assistant threats at the Objective by the Sea security conference in November.

What to Watch

  • Meta's Response: Will Meta acknowledge the vulnerability and release a patch? The company's silence so far raises concerns about its commitment to security.
  • Amazon's Block: Will other companies follow Amazon's lead in blocking Muse? This could limit the assistant's functionality and raise questions about its viability.
  • Security Conference: Wardle's presentation at the Objective by the Sea conference in November may provide more details on the vulnerability and other AI assistant threats.
  • User Awareness: How will users respond to the vulnerability? Will they continue to use Muse, or will they seek alternatives that offer better security and privacy?

Get the signal, not the noise.

One short email when it matters. No recaps of recaps.

SHARE

← All stories