Hacker News front pageDan Goodin6 min readintermediate
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Summary
A zero‑day in Meta’s macOS AI assistant Muse lets any local app or terminal command steal the user’s authentication token by changing an undocumented setting that redirects transcription to an attacker‑controlled server. The flaw enables a simple ClickFix‑style attack that can write files, snap pictures, and exfiltrate data, and was patched by Meta within 12 hours.
- Muse’s macOS app allows any local process to modify undocumented settings, exposing the auth token.
- Attackers can redirect the transcription endpoint to their server, gaining full control of the assistant.
- A single terminal command (ClickFix attack) can hijack Muse, write files, take pictures, and exfiltrate data like WhatsApp messages.
- Meta patched the vulnerability within 12 hours, but the root cause was design choices: cloud‑based transcription and unrestricted settings.
Security engineers and AI product developers need to understand the risks of giving AI assistants deep OS access and the importance of secure design choices.
6/10





