Meta Muse security: a Mac zero-day and a 6.8 GB filesystem export
Meta Muse, the personal AI agent Meta announced on September 8, had a bad Monday. Patrick Wardle disclosed a zero-day in the Muse Mac app that hands the account token to anyone who can run one terminal command, and developer Peter James asked Muse for its own filesystem and got a 6.8 GB zip of it. If you build AI agents, or let one onto your laptop, both findings are about decisions you will have…
Meta's AI agent, Muse, came under scrutiny on a Monday following the disclosure of two significant security vulnerabilities. Patrick Wardle discovered a zero-day exploit in the Muse Mac application, which would grant any attacker controlling access to a user's account with a single terminal command. Peter James then requested Muse to export its entire filesystem, receiving a 6.8 GB archive containing the root directory of the Linux sandbox.
This export included 113 sub-agent transcripts, roughly 20 internal manuals, and even a copy of OpenAI's Codex CLI.
Muse functions as a personal AI agent on Mac, granting users access to their files, camera, and even WhatsApp messages upon request. The app communicates with a separate server for voice transcription, but this server can be redirected, allowing attackers to intercept the account token and gain full control. Both findings underscore the importance of carefully considering the permissions granted to new AI agents and the potential risks they may pose to user data and privacy.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.