Zero-Day Flaw in Meta’s Muse AI Lets Malware Hijack macOS Assistant
A critical zero‑day vulnerability discovered in Meta’s Muse AI assistant for macOS could enable malicious software already running on a device to take control of the voice‑driven tool, intercept user commands, and exfiltrate authentication data.
Security researchers who examined the flaw found that once malware gains the same user privileges as the legitimate application, it can inject code into Muse’s process. This allows the attacker to rewrite the assistant’s prompt handling, effectively turning the AI into a conduit for further malicious instructions while remaining invisible to the user.
The issue is particularly worrisome because Muse is marketed as a productivity enhancer that listens for spoken queries and executes actions such as opening files, sending messages, or retrieving passwords. By hijacking the assistant, an adversary could capture sensitive credentials entered through voice commands, redirect the assistant to download additional payloads, or manipulate the output to trick the user into revealing more information.
Meta has not yet commented publicly on the vulnerability, and the company’s bug‑bounty program has not disclosed any related reports. The discovery was first reported by cybersecuritynews, which highlighted the ease with which existing malware could leverage the weakness without requiring elevated system privileges beyond those of the logged‑in user.
Experts say the flaw underscores a broader risk associated with AI‑driven assistants on personal computers. While these tools offer convenience, they also expand the attack surface, especially when they operate with deep system integration. Users are advised to keep macOS and all applications up to date, monitor for unexpected behavior from voice assistants, and consider limiting microphone access for non‑essential apps.
Meta is expected to release a patch in an upcoming software update, though the timeline remains unclear. In the interim, security professionals recommend employing endpoint protection that can detect anomalous process injection and restricting the execution of unsigned code. As AI assistants become more prevalent, the industry will likely see increased scrutiny of their security architectures to prevent similar exploitation vectors in the future.
Comments (0)
Be the first to comment.
Join the discussion