344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
A macOS bug could let other apps take over Meta’s Muse assistant. Amazon has also blocked Muse from shopping on its site.
In short: A security researcher says a zero-day flaw in Meta’s Muse app on macOS could let other programs take control of a user’s Muse account.
Meta launched Muse a few weeks ago as an AI assistant that can do tasks like booking appointments, filling out forms, and making purchases. To do that, users have to give Muse broad access to accounts like WhatsApp, email, and calendars, and also grant powerful permissions on their Mac, like access to files, the microphone, the camera, and location.
macOS normally tries to limit what apps can reach, especially sensitive things like your camera and files. According to macOS security expert Patrick Wardle, Muse’s design weakens some of those protections by letting any local app or command change certain hidden settings inside Muse.
Wardle says one setting can be abused to redirect Muse’s speech transcription (turning spoken words into text) away from Meta’s server and toward a server controlled by an attacker. If that happens, the attacker can capture a Muse login token (a secret key, like a valet key that can unlock and drive your car) and then take over the Muse account. Wardle says he built demo attacks that could write harmful files to disk or take pictures, sometimes without obvious warning.
Separately, Amazon began blocking Muse from using Amazon for shopping, calling it an “unauthorized AI agent” and asking Meta to remove Amazon from Muse’s experience.
Muse is designed to act on your behalf across many services, so a takeover could expose private messages, emails, and other personal data. Wardle also said a simple “ClickFix” style trick, which convinces someone to copy and paste a command, can be enough to start an attack.
Source: Arstechnica