This exploit enables an attacker to redirect the app’s transcription endpoint to a malicious server, effectively capturing the authentication token used to verify the user’s identity and gain full control over the account.
This vulnerability is significant because Muse requires extensive access to a user’s most sensitive data, including email, WhatsApp messages, and system resources like the microphone and camera, to perform tasks.
By bypassing Apple’s standard macOS security defenses, the flaw allows an attacker to leverage the AI assistant’s own high privileges to write malicious files or snap photos without the user’s knowledge.
The discovery arrives amid broader industry scrutiny of AI agents; Amazon has already begun blocking Muse from its site, citing security concerns and unauthorized behavior on its platform.
The breach is attributed to specific design choices, such as processing dictation in the cloud rather than locally on the device and allowing any software to alter sensitive configuration settings.
While Meta has promoted Muse as being built for privacy, Wardle’s findings suggest that the assistant can be compromised through common "ClickFix" attacks that trick users into running simple commands.
This affects any macOS user who has integrated the AI with their personal or professional accounts, as the exploit provides a permanent gateway for attackers to manipulate the agent and access private communications.