Un-Mused: How a Single Debug Setting Bypassed macOS Security in Meta’s AI Client
A flaw in Muse’s macOS client let code already running as the logged-in user redirect the app’s dictation endpoint, exposing voice input and an authentication token that could be used to act through the assistant’s granted access. This was a local-code-execution-to-agent-privilege escalation path—not a remote attack that could compromise a Mac by itself—and using the voice path was required.
Meta issued a hotfix on September 22, within hours of the disclosure. The case still illustrates how an AI agent’s broad app permissions can amplify a weaker local compromise. InfoQ has no article comment section; Meta characterized the practical risk as low because local malicious code was required.