Mark Zuckerberg, the founder and CEO of Meta, has aggressively promoted the privacy and security features of its newly launched AI assistant, Muse, asserting that it is “built from the ground up for privacy and security.” However, recent revelations surrounding a critical zero-day vulnerability raise significant concerns about its security. Additionally, Amazon has taken the unusual step of blocking Muse from its platform.
Launched just a few weeks back, Muse is marketed as an intelligent assistant capable of managing appointments, completing forms, and assisting with customer service functions. It aims to take proactive control of everyday tasks, enabling users to make purchases, generate images, draft documents, and link with their favorite applications and services seamlessly. Although currently available only as a macOS application—despite the absence of a Windows version—it integrates with users’ WhatsApp, email, calendar, and social media accounts. Notably, Muse possesses the capability to create tools on-the-fly for tasks where no existing solution is available.
Despite these ambitious claims, using Muse requires users to grant it access to a variety of accounts and services. This includes authenticating Muse with specific platforms, and since it operates on macOS, users must permit access to numerous system resources, such as file storage, microphone, camera, location services, and calendar data. These permissions are crucial, considering Apple’s stringent measures designed to safeguard these resources against unauthorized access, as they are deemed serious security risks. Unfortunately, Muse’s architecture undermines these critical protections.
The identified zero-day vulnerability allows any locally running application or terminal command unrestricted access to the token that authenticates users with Muse. Meta’s developers have configured the assistant so that any app or code executed on the macOS can manipulate a range of undocumented settings. While many of these settings are relatively benign (like adjusting dark mode), there’s one concerning option that permits changes to the endpoint for transcription services. Under normal circumstances, this endpoint is a server operated by Meta. If exploited, attackers can redirect this to their own server, gaining complete control over the Muse account by acquiring the authentication token.




