Meta patched a Muse flaw that let local malware hijack the AI agent
Security researcher Patrick Wardle showed that code already running on a Mac could redirect Muse's dictation traffic and capture its session token.
TLDR
Meta patched a flaw in the Mac client for its Muse AI agent after security researcher Patrick Wardle demonstrated a local hijack. Code already running as the logged-in user could change an undocumented dictation endpoint, intercept voice requests and capture the token used to access Muse. The proof of concept then exercised commands through the user's agent session. The attack required local code execution first, but it could inherit access the user had already granted Muse to connected services and device functions.
Meta patched a Muse flaw that let local malware hijack the AI agent
Security researcher Patrick Wardle showed that code already running on a Mac could redirect Muse's dictation traffic and capture its session token.
TLDR
Meta patched a flaw in the Mac client for its Muse AI agent after security researcher Patrick Wardle demonstrated a local hijack. Code already running as the logged-in user could change an undocumented dictation endpoint, intercept voice requests and capture the token used to access Muse. The proof of concept then exercised commands through the user's agent session. The attack required local code execution first, but it could inherit access the user had already granted Muse to connected services and device functions.

