Meta patched a zero-day in Muse about a day after it was disclosed, closing a hole that let any app or terminal command on a Mac take over a user’s Muse account. Any local code could change an undocumented setting that controls where Muse sends speech for transcription, and pointing it at an attacker’s server sent the account token along with the audio, according to Dan Goodin at Ars Technica. Patrick Wardle, the macOS researcher who found it, wrote working attacks that put files on disk and took pictures with nothing shown to the user, on an assistant that reaches WhatsApp, e-mail, calendar and social accounts plus the disk, mic, camera and location. Wardle called the hot fix a quick patch on September 22 but says a remote ClickFix route still worries him.






