The permission barrier erected by Apple has been bypassed by Meta AI Assistant via a workaround.
Patrick Wardle, founder of the Objective-See Foundation and a security researcher, has disclosed an unpatched zero-day vulnerability affecting Meta's newly released Muse macOS desktop client. Meta CEO Mark Zuckerberg previously claimed that this autonomous AI assistant was built with privacy and security as its core from the very beginning, but the vulnerability is reportedly able to be exploited by locally running software or Shell commands to hijack the application. Through this attack vector, unprivileged software can leverage the broad permissions previously granted to the assistant by users, bypassing macOS's standard security boundaries. As the company has not released an official security advisory nor coordinated with the CVE number assigning authority, the vulnerability does not have an official CVE ID at present.
The vulnerability stems from an undocumented configuration preference key named endo_voyager_dictation_endpoint. On macOS systems, local processes running as unprivileged users and arbitrary scripts can overwrite this configuration value without obtaining elevated administrator privileges or triggering the operating system's authorization prompt. During normal operation, this parameter is used to specify the cloud server endpoint that receives voice dictation audio and returns transcription results. Attackers only need to modify this setting to silently redirect the dictation traffic sent by the assistant to a server under their direct control.
From an exploit perspective, this vulnerability compromises both the confidentiality of input content and account credentials. When the user enables the dictation function, the desktop client will send the raw microphone audio as well as the valid authentication token associated with the victim's Muse account to the configured endpoint. Wardle demonstrated how an attacker can run a proxy server to seamlessly forward normal traffic back to Meta's servers while capturing authentication tokens and audio data, thus avoiding detection. After obtaining valid session credentials and gaining direct control over the command pipeline, attackers can also implement prompt injection attacks, appending hidden instructions to voice requests to force the assistant to perform unauthorized tasks in the background, such as stealing local documents or WhatsApp message records.
The technical significance of this vulnerability lies in the fact that it amplifies access permissions and erodes the platform's trust boundaries. Operating systems such as macOS rely on the Transparency, Consent, and Control (TCC) framework to restrict applications' access to hardware peripherals, files, contacts, and calendars. Since Muse is an agent that can interact with applications, calendars, emails, and files, users usually grant it extensive system permissions. Wardle pointed out that this vulnerability allows malicious actors to effectively turn the signed, trusted assistant into an attack surface by manipulating this agent without developing complex standalone information-stealing malware. A former Meta AI security engineering manager also expressed similar architectural concerns, stating that he would not use this software due to the inherent risks of deep integration.
Wardle has released a proof-of-concept exploit named not-a-mused, which demonstrates how a large number of commands can be executed through the compromised agent. This disclosure came shortly after Amazon banned Muse from accessing its shopping platform on the grounds that it did not comply with the automated agent access policy. After the public disclosure of the vulnerability, Meta deployed a hotfix for the Muse app for macOS. This fix removes this internal debug preference setting from the production client build, thus preventing local modification of the target address of the dictation server.
The company regards this vulnerability as an internal configuration defect and does not follow the formal CVE ID assignment process. David Singleton from Meta's Superintelligence Lab described the issue as a local configuration problem that requires prior code execution capabilities, and the engineering team resolved it by quietly removing the internal debug preference key from the production build. As can be seen from the comments of security professionals on related posts, the community does not agree with this statement. They pointed out that initial access can be easily obtained by using social engineering lures such as ClickFix, and bypassing Apple's Transparency, Consent, and Control framework has historically been very complex. In broader engineering discussions on Hacker News and Reddit, observers pointed out that Meta has centralized cross-device synchronization, full disk permissions, audio streams, and private chat records into a sandbox-free, signed agent whose debug endpoints are modifiable, which actually provides ordinary malware with an almost effortless channel to bypass the platform's protection mechanisms without triggering runtime alerts.
Original link:https://www.infoq.com/news/2026/09/meta-muse-zeroday/
This article is from the WeChat Official Account "InfoQ", written by Olimpiu Pop; translated by Tian Cheng, published by 36Kr with authorization.