9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
Meta has spent the last two weeks telling anyone who’ll listen how secure its new Muse personal AI agent is. The company boasted about its dedicated Secure VM, a monitoring system called Sentinel, and bug bounty rewards of up to $300,000. Mark Zuckerberg himself even publicly stated the agent is “built from the ground up for privacy and security.”
Then Patrick Wardle, macOS security researcher and friend of Security Bite, found a 0-day vulnerability in the Muse app on Mac that made the last 24 hours particularly not-a-musing (what Wardle comically named the finding).
If you’re struggling to keep track of the AI news cycle too, Muse is Meta’s new personal AI agent, which launched on Mac earlier this month. It’s less of a chatbot and more meant to do things for you across your apps and accounts, like sending emails, filling out forms, handling payments, and making purchases on your behalf. BUT to do all of that, you have to hand it a lot of access (mistake #1).
Wardle found that any app or Terminal command running locally on a Mac can change a number of undocumented Muse settings, no special macOS permissions needed. One of those settings, endo_voyager_dictation_endpoint, controls where your dictated prompts get sent.
An attacker can point that setting away from Meta’s servers, and toward one in their control. So the next time a user dictates a prompt, it goes to the attacker instead. From there, they can grab the token that authenticates your Muse account and use it to control the agent.

Wardle showed this off with a few proof-of-concept attacks, including writing malicious files to the Mac and even taking photos with the camera. He also used a hijacked Muse account to pull the location of a linked iPhone.
To be clear, this doesn’t give a remote attacker instant access to every Mac running Muse. It’s a local attack. They first need a way to run code on your machine. But all it takes is a ClickFix-style attack to trick a Mac user into pasting a command into Terminal. And voilà.
I recorded an entire Security Bite Podcast episode on why ClickFix is the #1 way to get malware on Macs today.
Wardle also pointed out that Apple already offers on-device dictation to developers. If Meta had used it, this bug wouldn’t exist. Instead, Muse sends your voice to its servers to be processed (mistake #2).
The good news is that Meta has reportedly pushed a fix. If you use Muse on Mac, update ASAP.
I recently had Patrick Wardle (and Kseniia from MacPaw) on the Security Bite Podcast to talk about all things Apple security and the upcoming Objective By The Sea v9 security conference in November. A fitting listen, all things considered.
Security Bite is 9to5Mac’s weekly deep dive into the world of Apple security. Each week, Arin Waichulis unpacks new threats, privacy concerns, vulnerabilities, and more, shaping an ecosystem of over 2 billion devices. Every other week on the Security Bite Podcast, he sits down with experts in the field to break down the most pressing topics.
Follow Arin: Twitter/X,LinkedIn, Threads
FTC: We use income earning auto affiliate links. More.


Comments