Skip to content
InYourGeek
visiteur@inyourgeek — shell
compléter historique ouvrirhelp
FR
AI· 3 min read

Meta's Muse AI assistant hands its token to any passing script

A zero-day lets any local app or terminal command hijack the authentication token of Muse, Meta's in-house AI assistant. That assistant has your accounts, your microphone and your camera.

A Mac laptop with a glowing AI assistant window, a microphone and camera icon lit up, and a stream of data leaving the screen towards an unknown server

On 21 September 2026, Ars Technica published an analysis of a zero-day in Muse, the AI assistant Meta shipped a few weeks ago. The gist fits in a single sentence: any app installed on the machine, or any command typed into a terminal, can take the agent over.

An assistant you handed everything to

Muse books appointments, fills in forms, handles customer service, shops, generates images, creates documents and plugs into your favourite apps. It runs on macOS and — oddly — has no Windows version at all. It works with your WhatsApp account, your email, your calendar and your social networks. And when the tool it needs doesn’t exist, it goes ahead and builds one.

For any of that to work, you have to authenticate it against every one of those services and grant it the resources macOS guards by default: writing files to disk, microphone, camera, location, calendar. Apple spent years building those gates, on the view that an installed app or a terminal command reaching for them is a threat. Muse takes the whole fence down.

The setting that should never have shipped

Meta’s developers arranged things so that any local app, whatever macOS permissions it holds, can change a long list of undocumented settings. Most are harmless — dark mode, for instance. Exactly one is not: the setting that names the endpoint your transcription is sent to. Normally that’s an address Meta operates. An attacker swaps in their own and walks off with the token that grants full control of the Muse account.

Patrick Wardle, the macOS security researcher who found the flaw, built several proofs of concept: writing malicious files to disk, taking photos — in many cases with no visible tell whatsoever, even for an attentive user. His summary to Ars Technica: “We can manipulate the agent and leverage its privileges to do whatever we want.” Why write a full-blown Mac infostealer when the victim has already installed one for you, and pointed it at their own inbox?

Two design decisions, one zero-day

The first: running dictation in the cloud, where Meta can log it, when macOS has been able to transcribe on-device for years. Wardle is unambiguous — make the other call and the attack simply doesn’t exist.

The second: letting every app on the machine drive every undocumented setting. The intent was presumably to let companion apps nudge the interface around, which is reasonable enough. Letting that same door decide where the user’s voice lands is a rather different proposition. “They don’t have to be perfect,” Wardle says of apps in this category — before adding that in Muse’s case, his impression is that nobody thought about security at all.

The gap with the press release

Mark Zuckerberg leaned hard on Muse’s security, describing it as “built from the ground up for privacy and security.” Meta published two blog posts in two weeks documenting the design decisions meant to keep an assistant with this much reach private. They land at a moment when internal tests of Anthropic and Google models ended in break-ins to third-party networks the engineers involved were not aiming at — the sort of episode that, between humans, ends up in front of a judge.

Meta did not respond to Ars Technica’s questions. Amazon, meanwhile, started blocking Muse on its site on Sunday.

The first consumer agent clever enough to build its own tools has, it turns out, built one for the burglar as well. Scrutinise the subscription price all you like — the real cost of going agentic was on the permissions screen you clicked through on day one.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.