Patrick Wardle’s Sep 21 disclosure: local apps can retarget Muse’s cloud dictation endpoint and steal the agent token. Amazon separately blocks Muse as an unauthorized purchase agent. Meta did not answer Ars. ClickFix + local code is the practical start.
Prompt Injection — One Hidden Setting Let Mac Malware Hijack Meta's Muse
What the video shows
Embed: Prompt Injection (YouTube ZyLKet85w9c). Creator walkthrough of the hidden-setting / Mac malware framing. Prefer with hedges over NONE; send readers to Ars for Wardle quotes, Amazon’s emailed statement, and Meta’s non-response. A thumbnail that says “hijack” is still describing a disclosed research chain, not a Meta CVE bulletin in this pack.
What’s new
AISN can soft-re-cover Muse’s launch. What is new is the security receipt: Wardle’s endpoint-hijack path into the Muse token, plus Amazon’s near-simultaneous agent block. The scarce job is to keep privilege abuse and merchant access policy in separate sentences.
Evidence
Ars Technica / Patrick Wardle (Sep 21). Goodin reports that Muse exposes a long list of undocumented settings controllable by any local app or terminal command — including the cloud endpoint used for dictation/transcription. Attackers point that endpoint at their own server, capture the Muse auth token, and then drive the assistant’s privileges (Wardle: “leverage the AI assistant itself” instead of writing a full stealer). PoCs include malicious file writes and camera snaps with little user indication. Design choices called out: cloud dictation instead of on-device transcription; any app controlling sensitive endpoints. Meta’s recent privacy/security posts claimed Muse was built for privacy and security; Meta representatives did not answer Ars’s emailed questions.
Amazon block (~12 hours before disclosure). Users saw Muse labeled an “unauthorized AI agent” violating Amazon’s Conditions of Use. Amazon’s emailed statement argues third-party purchase agents should operate openly and respect merchant participation decisions — the food-delivery / OTA consent analogy — and says it asked Meta to remove Amazon from the Muse experience. That is a commercial access fight, reportable in the same brief, not a substitute for Wardle’s technical finding.
ClickFix precondition. Wardle notes a simple ClickFix-style trick can get the local foothold. House voice keeps that hedge: this is not “Muse hacked from the open internet with zero user interaction” in the Ars account.
What this does not prove
- It does not prove Meta has publicly patched the setting in this package — Meta did not answer Ars.
- It does not prove Amazon’s block is caused by the 0-day — timing overlap ≠ identical finding.
- It does not prove remote, zero-click takeover without a local execution path.
- It does not redo the Sep 8 launch as today’s lead.
Bottom Line
Muse’s Sep 21 story is a token-theft 0-day via a hidden dictation-endpoint setting (Wardle / Ars), plus a separate Amazon unauthorized-agent block. Meta silent to Ars. ClickFix + local malware remains the practical on-ramp. Soft-re-cover the launch; lead the security receipts — and do not fuse merchant policy with the bug.