Meta has patched a vulnerability in its Muse assistant that could let an unprivileged local app or terminal command take control of the user’s AI-agent account. Because Muse can access files, messages, cameras, calendars and connected services, security researcher Patrick Wardle said an attacker could reuse those permissions instead of building specialized Mac malware.
The flaw allowed local processes to change an undocumented endpoint used for Muse’s cloud transcription. Redirecting it to an attacker’s server could expose the account token and allow malicious instructions to be inserted into a voice request. Wardle demonstrated proof-of-concept actions including writing files and taking pictures, sometimes without a visible warning.
Meta released a hotfix more than 12 hours after the report appeared. The company emphasized that the issue was not a remote exploit, but Wardle argued that a common ClickFix social-engineering trick could persuade a victim to run the required command. There is no report in the article that the flaw was exploited against users.
Muse needs unusually broad permissions to book appointments, fill forms and act across accounts. The incident shows why that convenience raises the security bar: a weakness in the agent can bridge protections that normally keep low-privilege software away from sensitive device capabilities.