We appreciate this report and have issued a hotfix to the Muse Mac app. This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low. Nonetheless, we have issued a hotfix to the app to address the issue.
We take every report of a possible security problem very seriously, including those that arrive as published exploit code (like this one). We strive to be extremely transparent about privacy and security in Muse as we know this is important to maintain your trust. Therefore, here’s a little more detail on this issue:
- Muse's dictation is powered by a server-side speech model. The app shipped with an internal setting that allows the endpoint used by this feature to be redirected to a different URL, which is useful during debugging and development.
- The setting lives in the app's local preferences, which macOS allows any program running under your user account to modify. Changing this requires malicious code already running on your Mac. This is not remotely exploitable, and it does not involve Muse's servers or the Secure VM that isolates agent tasks.
- Overriding this setting would let an attacker proxy audio dictation requests and capture the access tokens the Muse app uses to drive the Muse agent – expanding malware already present on your computer into the Muse agent. Our hotfix removes the endpoint setting from production builds entirely, which closes this vulnerability.
- We are grateful for the work of the security research community and potential security issues can be responsibly disclosed via our bug bounty program, which pays up to $300,000 for exactly this class of finding.
bugbounty.meta.com/