Meta's Muse has a zero-day. Verdict: REVERT.
Yesterday's stamp on Meta's Muse was NEEDS REVIEW.
Yesterday's stamp on Meta's Muse was NEEDS REVIEW. Overnight the review arrived twice: Patrick Wardle showed that any local app or one pasted terminal command can redirect Muse's transcription endpoint and walk off with the account token, and Peter James asked Muse for its own filesystem and got 6.8 GB of it (codename Hatch, Codex CLI in the image). Meta's answers: no reply to Ars, and "Not Applicable" from the bug bounty. Verdict: REVERT.
Read the written edition (English) ↗
What this video covers
- Yesterday's verdict, overnight's review
- The week: Amazon's wall, Wardle's 0-day, a 6.8 GB zip
- The 0-day: a dark-mode toggle next to your token
- ClickFix: one pasted command, dictation in Meta's cloud
- The export: 6.8 GB, codename Hatch, Codex CLI inside
Transcript
Yesterday's verdict, overnight's review
0:00 Yesterday I stamped Meta's Muse NEEDS REVIEW. Overnight, one pasted command took over a Muse account, and Muse zipped its own hard drive for a researcher, six point eight gigabytes. In this video, the zero-day, the export, and the AMD chip that never rolls zero. It's Tuesday, September 22nd, and this is The Daily Diff. So here is the diff.
The week: Amazon's wall, Wardle's 0-day, a 6.8 GB zip
0:22 Sunday night Amazon walled Muse off. Twelve hours later Patrick Wardle published a zero-day in the Muse Mac app. Monday, Peter James asked Muse for its own filesystem and got it. Also this week, AMD's random numbers skip zero, and Apple put ads in Settings you cannot close.
The 0-day: a dark-mode toggle next to your token
0:38 First, the zero-day. Muse on the Mac has more permissions than your bank. Your files, your camera, your WhatsApp. Apple spent a decade building walls around those, and Muse asks you to open every gate on day one, because that is the product. Patrick Wardle wrote The Art of Mac Malware. He found that any app on the Mac, or any terminal command, with no permissions at all, can change a long list of undocumented Muse
1:00 settings. Most are harmless, like dark mode. One is the server address where your voice gets transcribed. Point that address at your own server and you receive the transcription, plus the token that logs in to the Muse account. Wardle's line is that instead of writing a Mac stealer, you just leverage the AI assistant itself. His proofs of concept wrote files and took webcam photos. The delivery is a ClickFix, the attack where a fake error page tells you to
ClickFix: one pasted command, dictation in Meta's cloud
1:26 paste one command, and enough people do that it has a name. Half of Hacker News says that is not a zero-day, that is idiocy as old as time. True, and also why a login token should not live behind a dark mode toggle. Dictation could have stayed on the Mac. Meta chose the cloud, where Meta can log it. Second, the export.
The export: 6.8 GB, codename Hatch, Codex CLI inside
1:46 Peter James, who builds a coding tool called Mouse, asked Muse to archive every file it could see and send it to his Google Drive. Muse said sure. Two point seven gigabytes compressed, six point eight unpacked, the root filesystem of the Linux machine his agent lives on. Meta's internal name for Muse is Hatch. The home folder holds a soul file, an identity file and a memory file. Then a hundred and thirteen sub-agent transcripts and about twenty manuals for
2:13 payments, credentials and browser use. A config file lists connectors Meta has not announced, like Slack, Dropbox and Polymarket. The image also ships OpenAI's Codex CLI, apparently unused except for its sandbox tool, which Meta borrowed to run ffmpeg. Meta's flagship agent carries OpenAI's coding agent in the trunk, like a spare tire from the rival dealership. There were SSH key files, untested, and a nightly job called a dream that
2:40 reads your conversations and writes notes about you. His dream noted he had not asked for unsolicited NFL scores. The sandbox itself held, he says, and he stopped poking because it is production. He filed it with Meta's bug bounty.
Not Applicable: three parties, one week, one denial
2:52 Meta marked it Not Applicable. Half of Hacker News agrees, it is your own VM. Then read the launch post. Meta says a separate Sentinel agent approves everything that leaves the machine. The Sentinel approved a three gigabyte zip of the machine leaving the machine. Meta says Muse never sees your passwords. Wardle's proxy sees the token, which is the password.
3:10 Amazon says Muse appears to capture and store customer credentials. Ars emailed Meta questions and got nothing. Three parties, one week, and the only one saying there is no problem is the one selling it. Now the chip that will not roll a zero.
AMD: the die with 65,535 faces
3:24 In May a Brazilian assembly programmer named Jessé was drawing bar charts of random numbers and noticed his AMD Ryzen never rolled a zero. Sixteen-bit numbers, so about sixty-five thousand faces on the die. After eleven hours, the one face that never came up was zero. Intel rolls zeros all day. This week Hacker News reproduced it on Zen 2 and found the mechanism. The chip does produce zeros. It just raises the try-again flag every time the value is zero,
3:51 so any correct program retries and never sees one. Somebody at AMD wrote, if zero, report failure. A die with sixty-five thousand five hundred thirty-five faces, sold as fair. Does it matter? A one in sixty-five thousand bias will not break your TLS, and Linux mixes sources anyway. But Zen 2 launched in 2019 with the opposite bug, always returning all ones,
4:12 fixed by microcode. And last year AMD's own advisory for Zen 5 told developers to treat a zero as a failure and retry. The bug, written down as the fix. AMD's reply to Jessé, four months ago, read like ChatGPT. And Apple. iPhone users are finding banners at the top of Settings pushing
Apple: Settings ads you cannot close
4:30 iCloud plus, Apple Music trials and AppleCare, with a red badge until you act. There is often no dismiss button. The two ways out are waiting weeks, or paying. People who already pay for iCloud plus are seeing the iCloud plus ad, which Apple would call a bug and I would call a preview. Top comment on the thread says the Apple with ads is not the Apple that had taste. If you'd rather read this than hear me say it, the diff lands in your inbox every morning, free at the daily diff dot dev,
4:56 link below. So, today's verdict on Muse.
Verdict: REVERT, two reviews in one day
4:59 REVERT. Yesterday I said needs review. The review happened twice in one day, and the vendor's answer was silence and Not Applicable. Subscribe, hit the bell, and tell me in the comments if you'd have stamped it differently. And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
Sources
- Ars Technica, Dan Goodin — Muse has a serious 0-dayarstechnica.com
- Hacker News (105 pts)news.ycombinator.com
- mouse.dev, Peter James — I asked Meta's Muse for its filesystem and it sent me 6.8 GBmouse.dev
- Hacker News (263 pts)news.ycombinator.com
- Meta, Introducing Muse (Sep 8)about.fb.com
- Yesterday's episode — Amazon blocks Muse (NEEDS REVIEW)www.youtube.com
- flat assembler board, Jessé — AMD's RNG can't generate a 0board.flatassembler.net
- Hacker News (235 pts)news.ycombinator.com
- TechRadar, Alex Blake — Apple has added persistent 'ads' to iOSwww.techradar.com
- Hacker News (489 pts)news.ycombinator.com



