Meta’s Muse AI Assistant Has a Serious Security Flaw That Hands over Full Account Control

A security researcher found a way to fully hijack Meta’s new Muse AI app on the Mac, using nothing more than a locally running app or a single terminal command. The flaw undoes years of permission protections Apple built into macOS specifically to stop this kind of access.

Patrick Wardle, founder of the macOS security nonprofit Objective-See, disclosed the zero-day this week (via Ars Technica). It lands weeks after Meta launched Muse promising an assistant built with privacy and security in mind, one trusted enough to handle a person’s email, WhatsApp, calendar, and shopping.

Muse Mac App

One Undocumented Setting Opens the Door to Full Account Takeover

Muse is Meta’s AI agent for Mac, iPhone, Android, and the web. It launched earlier this month in the US, open to users 18 and older. It books appointments, fills out forms, sends emails, manages calendars, and can make purchases using a linked Stripe card. If a task needs a tool that doesn’t exist yet, Muse builds one on the spot.

None of that works without deep access to a person’s accounts and device. On the Mac, that means permission to the microphone, camera, file system, location, and calendar, the exact categories Apple normally locks down through its Transparency, Consent, and Control system.

Wardle found that Muse is expected to ship with a long list of undocumented internal settings, and any process already running on the Mac can change them with zero special privileges. Most control only cosmetic things like dark mode. One doesn’t. It is called endo_voyager_dictation_endpoint, and it decides where Muse sends the audio from voice dictation for transcription.

By pointing that setting at a server they control, an attacker with local code execution can:

  • Capture the authentication token tied to a person’s Muse account
  • Take full control of that account
  • Intercept dictated audio and prompts before they reach Meta’s servers
  • Use whatever access the victim already granted Muse, including WhatsApp, email, and calendar

Wardle summed up the impact plainly: “We can manipulate the agent and use its privileges to do whatever we want.” He built a working proof-of-concept for the attack and calls it not-a-mused.

The Flaw Undermines Years of Apple’s Permission Protections

Apple built its permission system for exactly this scenario. Local malware, in theory, still has to ask before touching a person’s mic, camera, files, or calendar, and the person has to approve it. Muse’s internal settings sit outside that entire system, reachable by any code already on the machine.

The bug isn’t remotely exploitable on its own. It needs a first foothold, either existing malware or a social engineering trick that talks someone into pasting a command into Terminal. Once that foothold exists, Muse turns it into full control of an assistant wired into someone’s email, WhatsApp, and calendar.

Meta has described Muse’s security architecture in detail since launch. Each account runs inside an isolated virtual machine called Muse Secure VM. A separate system called Sentinel is supposed to be the sole authority over which services and internet traffic Muse can reach, swapping in one-time tokens so Muse itself never touches real passwords or payment details. Meta CEO Mark Zuckerberg has promoted Muse as central to his vision of personal superintelligence and said the assistant was designed with privacy and security in mind from the start. Meta isn’t the only company facing pointed questions about how much control users and regulators hold over what an AI assistant can access, the same fight playing out in Apple’s ongoing Siri AI dispute with EU regulators.

Amazon Cut Off Muse Hours Before the Flaw Went Public

Meta’s security messaging took a second hit the same week. Amazon started blocking Muse from its site on Sunday, roughly twelve hours before Wardle’s disclosure went public. Amazon hasn’t detailed its reasoning, but the timing adds more pressure on Meta’s claims about how much control people have over the assistant.

Wardle plans to walk through the full technical breakdown of the exploit at the Objective by the Sea security conference in November.

Newsletter
Never miss an Apple story
One email a day, the news that matters. No spam, unsubscribe anytime.
About the Author

Imran Hussain is the founder and editor of iThinkDifferent, which he launched in 2008 to cover Apple news, reviews, and how-to guides. He has spent over 15 years writing about iOS, macOS, and the wider Apple ecosystem, with a focus on hands-on guides - installing developer betas, troubleshooting, and walking through new features on his own devices. Based in Dubai, he also loves to cover photography, gaming, and the tech industry more broadly on his social media profiles.

Leave a Reply