Lilith Lilith.
Editorial illustration: Meta quietly patches Muse hole, agent was hijacked via unmonitored settings
Lilith illustration · editorial remix

The route through unmonitored metadata

Meta's new macOS app, Muse, contained a zero-day vulnerability that allowed complete control over the AI agent. Security researcher Patrick Wardle discovered that Muse left its undocumented settings completely open. This meant that any locally running code could alter the assistant's configuration.

Wardle demonstrated that by redirecting transcription processing parameters, data could be diverted from Meta's servers directly to an attacker's endpoint. This granted access to the Muse account and forced the assistant to take screenshots or write malicious files to disk, mostly without any warning to the user.

Who controls the AI controller

The incident hits two sensitive points: architecture and reputation. Meta chose to process dictation in the cloud instead of locally on the device, while simultaneously failing to secure the app's local configuration. According to Wardle, this highlights a failure of engineers to consider security from the very beginning of the design phase.

An attacker doesn't need to write complex Mac malware to steal passwords or files. Instead, they can exploit the privileges and capabilities of the AI assistant itself. The agent designed to help thus becomes an ideal Trojan horse for system manipulation.

A defense that dampens panic

Meta released a patch within hours of the report's publication. David Singleton of the Superintelligence Labs emphasized that this was a local privilege escalation, not a remote exploit. For the attack to work, the attacker already needed to have malicious code running on the victim's machine under their user account.

The practical risk to the average user was therefore very low, according to the company. Still, it's an uncomfortable PR hit at a time when Meta is aggressively pushing Muse against ChatGPT. During its first 12 days in the US and Canada, the Muse app reportedly amassed more downloads than ChatGPT did during its debut.

The difficult adolescence of agentic systems

The real issue here isn't the patch itself, but the architecture. If agents are given privileges to manipulate the operating system, their communication lines and settings must be locked down against local tampering.

While Amazon is blocking Muse for exploring its platform without permission, this incident shows that AI agents pose an internal risk as well. The ability to read the screen and trigger actions means that any isolation flaw turns the assistant into a perfect weapon. The market will be watching closely to see if future updates add more robust local barriers.

Lilith's verdict

Building an agent that reads the screen and leaving its config files unlocked for all processes is amateur hour. Meta may have shipped a fast patch, but the architectural shortcut speaks volumes.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗