Signal

A researcher says a flaw in Meta's Muse app for Mac lets any app or terminal command gain access to the token that authenticates users to their Muse account

First reported by Ars Technica ·

The signal ●●●● Compiled by AI from Ars Technica, Techmeme, TechCrunch, GitHub and RuntimeWire
Why you might care

Any app or terminal command can now steal your Muse AI assistant account access.

What happened

A critical zero-day vulnerability has been discovered in Meta's Muse AI assistant for macOS, allowing any locally installed application or terminal command to hijack user accounts. Security researcher Patrick Wardle found that the flaw enables malicious actors to gain access to the authentication token that grants Muse control over user data, including WhatsApp, email, and calendars. This bypasses macOS security protections designed to prevent unauthorized access to sensitive resources. Wardle demonstrated that attackers could exploit this by redirecting Muse's transcription endpoint to their own server, thereby capturing the authentication token. The vulnerability raises significant doubts about Meta's claims of Muse being built with privacy and security at its core. Coinciding with this discovery, Amazon began blocking Muse from its platform, citing violations of its Conditions of Use for unauthorized AI agents making purchases.

What it means

This vulnerability highlights a significant gap in how AI assistants are being secured, particularly those with broad access to user data and system resources. The fact that Muse bypasses fundamental macOS security measures suggests a rushed development cycle or insufficient security testing by Meta, potentially setting a concerning precedent for future AI agent deployments. The incident underscores the increased risk users face as AI tools become more integrated into daily workflows, demanding a higher security bar than traditional applications.

The broad implications extend to how third-party services will interact with and vet AI agents. Amazon's decision to block Muse, stating that "third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions," signals a growing trend of platform gatekeepers scrutinizing AI agent behavior and access. This could lead to stricter API access policies and new industry standards for AI agent security and transparency.

AI-written summary. May contain errors.

Meta Crypto