Tuesday, September 22, 2026
Tech Beat
Sep 21, 2026, 10:24 PMCybersecurity

Meta Muse Zero-Day Lets Any Mac App Hijack the AI Assistant

Meta's macOS AI assistant Muse exposes account tokens through a zero-day, enabling covert device abuse while Amazon blocks it from shopping on its website.

Listen to this briefingAudio briefing

Summary

On September 21, 2026, macOS security researcher Patrick Wardle disclosed a Muse zero-day weeks after Meta launched the Mac-only AI assistant. Any installed app or terminal command, regardless of its macOS permissions, can change undocumented Muse settings, including the server handling cloud transcription. Redirecting that endpoint gives an attacker the authentication token and complete, persistent control of the Muse account. A proxy can modify voice prompts to execute commands, exfiltrate a WhatsApp archive, write malicious files, or take photos, often without alerts. Wardle demonstrated that a ClickFix-style trick and one unprivileged terminal command can trigger the flaw.

The exposure is severe because Muse can make purchases, book appointments, fill forms, handle customer service, create images and documents, build missing tools, and access WhatsApp, email, calendars, social accounts, files, location, microphone, and camera after user authorization. Wardle said macOS on-device transcription would have prevented this attack, while Meta chose cloud processing that it can log and allowed every app to alter the endpoint. Meta, despite Mark Zuckerberg's security claims and two security posts in two weeks, did not answer questions. Roughly 12 hours before disclosure, Amazon blocked Muse as an unauthorized AI agent, said it violated Amazon's Conditions of Use, and asked Meta to remove Amazon from the experience. Wardle, Objective-See Foundation founder, author of The Art of Mac Malware, and former NASA and National Security Agency employee, plans further details at November's Objective by the Sea conference.

Positives

  • Wardle's proof-of-concept attacks expose the zero-day before users place greater trust in Muse's extensive permissions.
  • macOS already supports on-device transcription that Wardle says would have prevented this attack route.
  • Amazon began blocking Muse roughly 12 hours before disclosure and asked Meta to remove its marketplace from the assistant.
  • Wardle plans to detail the vulnerability and broader AI assistant threats at Objective by the Sea in November.

Risks & concerns

  • Any local app or terminal command can redirect Muse transcription and capture the token controlling a user's account.
  • Muse's access to WhatsApp, email, files, location, microphone, camera, calendars, and social accounts magnifies the potential damage.
  • Attackers can modify voice prompts, steal WhatsApp archives, write malicious files, and take photos without visible warnings.
  • A simple ClickFix-style attack may compromise Muse without first obtaining privileged macOS access.
  • Meta chose loggable cloud transcription over an available on-device alternative and did not answer questions about the vulnerability.
  • Amazon says Muse operates as an unauthorized AI agent that violates its Conditions of Use.
Primary sourceAI - Ars Technicahttps://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecuritySep 18

FBI, Coast Guard Board Two Hacked US-Bound Oil Tankers

CybersecuritySep 18

Anthropic’s Claude Helps Hacktron AI Breach OpenAI Account

CybersecuritySep 16

ShinyHunters Leaks Florida DAVID Vehicle Records After Breach