A serious security vulnerability was found in Meta’s Muse, an AI assistant capable of performing actions on behalf of users. The vulnerability, identified by macOS security researcher Patrick Wardle, allowed malware on the computer to seize Muse’s authentication key and direct the agent using its existing permissions. In attack demonstrations, photos could reportedly be taken and malicious files could be attached without showing the user a prominent warning. The issue stemmed from the fact that the server address to which voice commands were sent could be changed through a user-invisible setting without requiring additional macOS permission. Meta said the vulnerability could not be exploited remotely on its own and that malicious code had to be present on the device beforehand. As a result, the operations could appear to the operating system as if they had come from the trusted Muse application. The company released an emergency update for macOS.
Why it matters
The incident shows that the security boundaries of AI tools acting on behalf of users are determined not only by how commands are interpreted, but also by how authentication information and operating system permissions are protected. The risk concerns Muse users whose devices already contain malware rather than a remotely accessible attack against everyone; in this situation, existing permissions can be abused without the attacker needing to obtain new ones. The fact that actions such as taking photos and attaching files could be performed without a prominent warning shows that user control is a separate layer of security in such tools. Although the emergency update addressed the issue, preventing the abuse of user-invisible settings and applications considered trusted remains an open area for oversight.
Background
Meta is not a new name in the FikirPilot archive: we have published 29 articles mentioning the name in the last 90 days; the latest is dated September 26, 2026.