Muse, Meta's newly launched artificial intelligence (AI) personal assistant, was targeted by a zero-day vulnerability discovered just weeks after its release. This flaw had the potential to allow an attacker to take control of the assistant on a Mac computer and use its inherent privileges to execute actions on the system.
The discovery was made by macOS security expert Patrick Wardle, who issued an alert about the issue. According to the researcher, an attacker could exploit the permissions that Muse requires to modify a setting related to the voice transcription system.
Normally, the application sends the transcription to a server managed by Meta. However, due to the flaw, the destination address could be swapped for a server controlled by the attacker. This would enable the acquisition of the token responsible for authenticating the Muse account.
With this token in hand, the aggressor would not necessarily need to install specific malicious software to steal data. Instead, they could directly take over the assistant itself, leveraging the privileges Muse already possesses on the computer.
One of the methodologies demonstrated by Wardle involves a variation of the technique known as ClickFix, a form of social engineering used to convince users to execute commands on their devices. In this scenario, a server controlled by the attacker would act as an intermediary between Muse and Meta's server. After the user provides a voice command, the malicious server could inject an instruction for the assistant to perform a harmful action.
As an example, Ars Technica cited the possibility of sending a file containing all WhatsApp messages to the attacker. Furthermore, the Muse authentication token would be transmitted to the malicious server, ensuring the attacker maintains control over the assistant's account.
Wardle emphasizes that the attack is particularly alarming because it exploits the AI agent itself, eliminating the need to develop dedicated data collection software. He told Ars Technica: 'We can manipulate the agent and leverage its privileges to do whatever we want.'
More information about the vulnerability
The researcher points out that one of the design decisions that facilitated the attack was Meta's choice to process voice transcription in the cloud. The macOS operating system has native features for dictation and transcription directly on the device. In Wardle's analysis, if Meta had chosen this alternative, the demonstrated attack would not be viable.
Another point raised relates to the ability of applications to control undocumented Muse settings. While some of these settings have minor detrimental functions, one specifically allows changing the address used for processing transcriptions. The combination of these two choices opened a path for a local command or application to modify the destination of sensitive information processed by the assistant.
Following the disclosure of the flaw, Meta announced that it had released a hotfix to resolve the issue, and this update was made available approximately 12 hours after Wardle published the details. The company also classified the vulnerability as one that could not be exploited remotely. However, Ars Technica noted that a variation of ClickFix attacks could be employed to persuade a user to execute the necessary code on their own computer.
Prior to the fix, Meta had promoted Muse as an assistant designed from the outset with a focus on security and privacy. The company implemented Muse Secure VM, an isolated virtual environment where the agent was supposed to operate with specific protections. The company claims that this environment was designed to provide protection, security, and privacy mechanisms while Muse performs tasks on behalf of the user.
The discovery of the vulnerability coincided with the moment Amazon began preventing Muse from making purchases on its platform. Users attempting to use the assistant to acquire products received a notification stating that Muse was an unauthorized AI agent and violated Amazon's terms of service. Amazon also asked Meta to remove the platform from its shopping experience, asserting that third-party applications making purchases on behalf of consumers must operate transparently and respect service decisions regarding their participation in such interactions.
Muse was introduced by Meta in early September and is currently available for macOS, but there is no version for Windows. The original article about Meta's new AI assistant facing a serious security flaw that could put Mac users at risk was initially published in Olhar Digital.
