Meta Patches Muse macOS Debug Setting That Exposed Audio, Tokens and Agent Permissions

সম্পর্কিত মডেল/ভেন্ডর: Meta AI বিক্রেতা
Meta Patches Muse macOS Debug Setting That Exposed Audio, Tokens and Agent Permissions

Security researcher Patrick Wardle, founder of the Objective-See Foundation, disclosed a zero-day vulnerability in Meta’s newly released Muse desktop client for macOS. Initially unpatched, the flaw allowed locally executing software or shell commands to take control of parts of the autonomous AI assistant’s workflow and exploit permissions the user had already granted it. The disclosure contrasted with Meta CEO Mark Zuckerberg’s assurances that privacy and security were foundational to the assistant. No official CVE identifier was assigned, and Meta did not issue a formal security advisory or coordinate assignment with a CVE Numbering Authority.

Article image

A configurable endpoint exposed dictation traffic

The issue centered on an undocumented preference named endo_voyager_dictation_endpoint. Local processes or scripts running as an ordinary user could change it without administrator privileges or an operating-system authorization prompt. Normally, this setting identified the cloud service that received voice recordings and returned transcriptions. Replacing its value redirected dictation traffic to an attacker-controlled server.

When dictation was activated, Muse sent both raw microphone audio and a valid Muse account authentication token to that destination. Wardle demonstrated a proxy that collected the recordings and tokens while forwarding legitimate requests to Meta’s servers, allowing normal operation to continue and making interception less apparent.

Access to session credentials and the request pipeline also enabled prompt injection. An attacker could insert concealed instructions into voice requests, directing the assistant to carry out unauthorized background actions, including extracting local documents or WhatsApp message histories.

Article image

Agent permissions amplified local access

The security impact extended beyond traffic redirection. Apple’s Transparency, Consent, and Control framework restricts applications’ access to resources such as peripherals, files, contacts and calendars. Muse’s ability to work across applications, calendars, email and files encourages users to authorize broad access.

Article image

Wardle argued that compromising the assistant let attackers reuse those authorizations instead of building a sophisticated standalone information-stealing tool. The signed, trusted application could become the mechanism for accessing protected resources. A former Meta AI security engineering manager also expressed concern about the architecture, saying its deep integration made them unwilling to use the software.

Wardle released a proof of concept called not-a-mused that demonstrated numerous commands executing through the compromised agent. The disclosure followed Amazon’s decision to block Muse from its shopping platform over violations of its automated-agent access policies.

Hotfix and disagreement over severity

After public disclosure, Meta shipped a hotfix that removed the internal debugging preference from production macOS builds, preventing that setting from changing the dictation server destination. The company handled the problem as an internal configuration defect rather than pursuing formal CVE assignment.

David Singleton of Meta Superintelligence Labs emphasized that exploitation required code already running locally and characterized the issue as a configuration problem. Security professionals responding to that position argued that social-engineering techniques such as ClickFix can provide initial execution relatively easily, whereas bypassing Apple’s consent controls is ordinarily much harder.

Discussions on Hacker News and Reddit raised similar architectural concerns. Commenters argued that combining device synchronization, full-disk permissions, audio and private chat histories inside an unsandboxed, signed agent with a changeable debug endpoint could let ordinary malware reach protected data through the assistant without obvious alerts.

এই নিবন্ধটি শেয়ার করুন