Meta has patched a vulnerability that allowed any locally running app or terminal command to take control of a user’s Muse AI agent. Security researcher Patrick Wardle found that software without special macOS permissions could alter an undocumented transcription setting and redirect the agent to an attacker’s server.
That redirect exposed the token used to authenticate the Muse account. An attacker could then use permissions already granted to the assistant, potentially writing files or taking pictures without a visible warning. Muse can access email, calendars and social accounts, make purchases and interact with protected device resources, making the flaw more consequential than a typical application bug.
Wardle demonstrated several proof-of-concept attacks. He argued that keeping dictation on the device, rather than sending it to a configurable cloud endpoint, would have removed this path. He also questioned why any local process could modify sensitive internal settings.
Meta released a hotfix after the report went live. The incident shows the security risk of desktop agents that accumulate broad privileges: even if each permission is granted legitimately, a weakness in the agent can bundle those rights into a powerful route around operating-system protections.