Patrick Wardle's Muse zero-day let any local app or terminal command take over the agent, hours after Amazon started blocking it
Ars Technica reports that Meta's macOS Muse app lets any local process change a long list of undocumented settings, including the endpoint that receives cloud dictation. Pointing that endpoint at an attacker's server hands over the account token and full control of the agent. Wardle built proof-of-concept attacks that write files to disk and take photos with no visible sign to the user, and Meta shipped a hotfix more than 12 hours after disclosure. Around 12 hours before the disclosure, Amazon began rejecting Muse as an 'unauthorized AI agent' under its Conditions of Use, which The Verge confirmed. Two lessons for anyone building a privileged desktop agent: keep settings that route sensitive data out of reach of arbitrary local processes, and expect big merchants to block agents that don't identify themselves.
Source
↳ Follow the thread