AI Newsway

One Undocumented Setting Turns Meta's Muse Into an Attacker's Tool, Researcher Finds

Repointing where dictation is transcribed hands over the account token β€” and a ClickFix-style lure is enough to trigger it

|4 min read0
AI Summary
Security researcher Patrick Wardle disclosed a zero-day in Meta's Muse assistant on September 21, 2026. Any locally installed macOS app or terminal command can change Muse's undocumented settings, including the server where dictation is transcribed, which redirects the account authentication token to an attacker. A ClickFix-style lure is enough to trigger it, with no prior device compromise required. Meta has not announced a fix.
A key resting on a laptop keyboard β€” Muse's account token, redirected by a single writable setting, is the key in this case
A key resting on a laptop keyboard β€” Muse's account token, redirected by a single writable setting, is the key in this case

Among the undocumented settings that any locally installed macOS app can flip inside Meta's Muse assistant, most are cosmetic β€” dark mode and similar. One is not. It controls the server address where dictated speech gets transcribed, and changing it redirects the authentication token that grants full control of a user's Muse account to whoever is listening. Security researcher Patrick Wardle disclosed the zero-day, first reported by Ars Technica, on September 21.

Key takeaways

  • Any local app or terminal command can alter Muse's undocumented settings regardless of the macOS permissions it holds, including the transcription endpoint.
  • Redirecting that endpoint delivers the account token to an attacker, who can then proxy prompts and issue commands with the assistant's own privileges.
  • Exploitation does not require a pre-compromised machine β€” Wardle showed a variation of the ClickFix social-engineering lure is sufficient.

How the exploit chain works

The relevant design decision is that Muse sends dictation to Meta's cloud for transcription rather than keeping it on the device, even though macOS has offered local speech processing for years. That creates a network endpoint, and the endpoint is user-writable by any process.

An attacker who repoints it can sit between the user and Meta as a proxy. Once a voice prompt passes through, the attacker's server appends an instruction of its own β€” Wardle's example was exfiltrating an archive of WhatsApp messages. Because the token travels to the malicious server alongside the prompt, access does not end when the session does.

Wardle told Ars he built working proofs of concept that wrote files to disk and captured photos, in many cases without any signal an attentive user would notice. Rather than authoring a comprehensive macOS stealer, he said, an attacker can simply borrow the assistant's privileges.

Why the permission model matters here

To function, Muse requires authentication to a user's accounts plus broad macOS entitlements: disk writes, microphone, camera, location and calendar access. Apple spent years building those consent gates precisely because installed apps and terminal commands should not reach those resources freely. An AI assistant granted all of them becomes a single high-value target, and a flaw in it inherits every permission the user approved.

The standard rebuttal β€” that all bets are off once a device is compromised β€” does not apply cleanly. ClickFix, the technique Wardle adapted, works on uncompromised machines by convincing people to paste a command themselves.

Meta's position, and Amazon's

Mark Zuckerberg has promoted Muse as built from the ground up for privacy and security, and Meta published two posts in as many weeks describing the design work behind that claim. The company did not respond to emailed questions from Ars about the vulnerability.

Separately, roughly twelve hours before the disclosure, Amazon began refusing Muse traffic on its storefront, telling users the assistant was an unauthorized AI agent in violation of its Conditions of Use. Amazon said third-party applications that purchase on a customer's behalf should operate openly and respect a service provider's decision about whether to participate, comparing the arrangement to delivery apps and online travel agencies, and asked Meta to remove Amazon from the experience.

What comes next

Wardle β€” who founded the Objective-See Foundation, wrote The Art of Mac Malware series, and previously worked at NASA and the National Security Agency β€” plans to present the vulnerability and related assistant threats at the Objective by the Sea conference in November. No fix had been announced at the time of disclosure.

The broader lesson is not specific to Meta. An agent that asks for inbox, calendar and payment access is asking to be trusted with the whole device, and a single writable setting is enough to undo that trust.

FAQ

Does the Muse zero-day require malware on the machine first?

No. Wardle demonstrated that a variation of the ClickFix technique, which tricks a user into running a command themselves, is enough. Any local process can then change the setting, regardless of its macOS permissions.

Has Meta patched the vulnerability?

Not as of the disclosure. Meta did not answer questions about the flaw, and no fix or mitigation had been published. Wardle intends to detail the issue at a security conference in November.

Why did Amazon block Muse?

Amazon said Muse was operating as an unauthorized agent in breach of its Conditions of Use, and argued that agents making purchases on a customer's behalf should do so openly and with the retailer's consent. The block began about twelve hours before the zero-day became public.

How do you feel about this article?

SJ

Discussion

Sign in to post
Loading...

Related articles

Huawei Pulled the Ascend 960 Forward Nine Months. Scale Is the Argument, Not the Die
Tech & Business

Huawei Pulled the Ascend 960 Forward Nine Months. Scale Is the Argument, Not the Die

Huawei used its Connect conference to move the Ascend 960DT up by three quarters to the first quarter of 2027, pairing it with a 4,096-accelerator Atlas SuperPo...

Seung Jung4 days ago
Judge Voids Pentagon Supply Chain Risk Label on Anthropic as Unlawful Retaliation
Tech & Business

Judge Voids Pentagon Supply Chain Risk Label on Anthropic as Unlawful Retaliation

A 59-page order found the Pentagon retaliated against Anthropic for criticizing the government, violating the First and Fifth Amendments.

Seung Jung25 days ago
AWS Buys DuckLabs, and DuckDB's Extension Stack Is About to Open Up
Tech & Business

AWS Buys DuckLabs, and DuckDB's Extension Stack Is About to Open Up

AWS will acquire DuckLabs in early September. DuckDB stays MIT-licensed under an independent foundation, and the extension stack is set to open up.

Seung Jung25 days ago
Crusoe Raises $3.9B at a $30.9B Valuation and Bets on Data Centers You Can Truck In
Tech & Business

Crusoe Raises $3.9B at a $30.9B Valuation and Bets on Data Centers You Can Truck In

Data center developer Crusoe announced on Thursday the initial closing of a $3.9 billion Series F at a $30.9 billion post-money valuation. Atreides Management,...

Seung Jung4 days ago
Nvidia Spent $27 Billion Without Filing a Single Merger Notice. The DOJ Wants to Know Why.
Tech & Business

Nvidia Spent $27 Billion Without Filing a Single Merger Notice. The DOJ Wants to Know Why.

Antitrust enforcers have opened their first real examination of the deal structure that has replaced the acquisition in AI: Nvidia has received a formal Justice...

Seung Jung9 days ago
Amazon Triples Its Nvidia Order to 2 Million GPUs
Tech & Business

Amazon Triples Its Nvidia Order to 2 Million GPUs

Amazon is adding 2 million more Nvidia GPUs to AWS just five months after committing to 1 million, even as it scales its own Trainium and Graviton silicon.

Seung Jung26 days ago