Eigen RadarAI
Analysis

A local Muse setting exposed the account token, and Meta patched it

A setting in Meta's Muse assistant for macOS let local code redirect transcription and capture the account token, Ars Technica reported. The flaw is not described as a remote break-in of an untouched Mac: the attacker first needs code running as the user. The Verge reported that Meta then shipped a patch for the app. What a stolen token could reach still depends on the permissions the owner had already granted Muse.

Artificial Intelligence··Evening
A daylight desk with a laptop showing a waveform, a cabled box beside it, and a small metal token.

Local code could move the transcription endpoint

Ars Technica reported that security researcher Patrick Wardle found any local app or terminal command could change Muse's undocumented settings, regardless of ordinary macOS permissions. Redirecting the transcription endpoint to an attacker server also sent the Muse account token there. The Verge described the same bug: an undocumented setting let local code point cloud transcription away from Meta, and the account token travelled with that traffic.[1], [2]

The path starts with code already on the Mac

The Verge reported that the exploit required local access and gave an attacker who already had code running as the user a way to control the agent. Ars Technica's account is the same shape: the setting change is available to processes on the machine, and Wardle's demonstrations included writing files and taking pictures through Muse. Neither report describes a remote entry that compromises a Mac with no local code at all.[1], [2]

Meta shipped a patch after the report

The Verge reported that Meta issued a patch for the Muse macOS app after the flaw became public. Ars Technica, writing up Wardle's finding, said Meta had not answered its questions at the time of that report. The patch is The Verge's later development; the token exposure and the local setting change are the facts both outlets describe. A patched app does not by itself say which accounts were reached before the fix.[1], [2]

References

  1. News sourceArs TechnicaMeta Muse's macOS flaw exposed its account token to local apps↩1↩2↩3
  2. News sourceThe VergeMeta patches the Muse macOS flaw that exposed the account token↩1↩2↩3