Security flaw raises concerns over Meta’s Muse AI agent
Meta’s newly launched AI assistant Muse is facing scrutiny over a serious security vulnerability that could allow attackers to take control of an account by exploiting permissions already granted to the agent.
The issue emerged shortly after Muse gained rapid popularity in the United States, reaching the top of Apple’s free App Store rankings. Unlike conventional chatbots, Muse is designed to carry out tasks on behalf of users, including booking appointments, filling out forms, handling customer-service requests, browsing websites and making purchases.
Security researcher Patrick Wardle discovered a zero-day vulnerability affecting the macOS version of Muse. According to his analysis, locally running applications or terminal commands could modify undocumented settings within the assistant, including the endpoint used to process voice transcriptions.
By redirecting transcription data to an attacker-controlled server, the vulnerability could expose the authentication token associated with a Muse account. That token could then give an attacker extensive control over the account and allow them to take advantage of permissions that the user had previously granted to the AI assistant.
Wardle demonstrated proof-of-concept attacks showing that Muse’s existing privileges could potentially be used to perform actions such as writing files to a computer or accessing the camera. He also described a variation of the increasingly common ClickFix social-engineering technique that could help trigger the vulnerability by persuading users to execute malicious commands.
The discovery highlights a broader security challenge associated with agentic AI. Giving an AI system the ability to interact with email, calendars, messaging services, browsers and other applications can make it considerably more useful, but it also means that a successful compromise could have consequences beyond those normally associated with a traditional chatbot.
Meta has promoted Muse as an assistant designed with security and privacy controls, including safeguards intended to prevent unauthorized actions and mechanisms that require user approval for sensitive operations. Ars Technica reported that Meta released a hotfix for the zero-day after the vulnerability became public.
The security concerns have emerged alongside a separate dispute involving Amazon. The e-commerce company blocked Muse from shopping on Amazon.com, arguing that the agent accessed the site without identifying itself as an AI agent and without Amazon’s agreement. Amazon said third-party applications making purchases on behalf of customers should operate transparently and respect the decisions of service providers.
Meta, for its part, has said that Muse does not have visibility into users’ passwords or payment information and that credentials provided by users are stored securely. The company’s description of Muse says the assistant can interact with websites through its own browser when no public application programming interface is available.
The two developments are separate, but together they illustrate some of the difficulties facing companies developing AI agents capable of acting independently online. As these systems gain access to more accounts, devices and services, security researchers and technology companies face growing pressure to ensure that convenience does not come at the expense of user control and data protection.
Muse’s early popularity suggests that consumers are increasingly willing to delegate complex online tasks to AI systems. The vulnerability, however, demonstrates why the security architecture surrounding such agents is becoming as important as the capabilities themselves. A compromised chatbot may produce incorrect information, but a compromised agent with access to real accounts can potentially take actions with direct consequences for its user.
-
21:15
-
21:00
-
20:47
-
20:30
-
20:15
-
20:05
-
20:00
-
19:30
-
19:15
-
19:00
-
18:50
-
18:42
-
18:35
-
18:20
-
18:15
-
18:05
-
17:45
-
17:30
-
17:15
-
17:14
-
17:12
-
17:00
-
16:57
-
16:47
-
16:30
-
16:27
-
16:20
-
16:18
-
16:16
-
16:12
-
16:00
-
15:45
-
15:31
-
15:27
-
15:22
-
15:15
-
15:00
-
14:54
-
14:45
-
14:36
-
14:30
-
14:14
-
14:00
-
13:45
-
13:30
-
13:05
-
12:47
-
12:30
-
12:24
-
12:15
-
12:12
-
11:58
-
11:41
-
11:25
-
11:17
-
11:14
-
11:11
-
11:00
-
10:47
-
10:30
-
10:30
-
10:15
-
10:00
-
09:42
-
09:38
-
09:25
-
09:18
-
09:09
-
08:45
-
08:30
-
08:15
-
00:45
-
00:30
-
00:15
-
23:55
-
23:45
-
23:35
-
23:30
-
23:15
-
23:00
-
22:45
-
22:32
-
22:15
-
22:05
-
21:54
-
21:45
-
21:30