Meta Muse Zero-Day Lets Any Mac App Hijack the AI Assistant
Meta's macOS AI assistant Muse exposes account tokens through a zero-day, enabling covert device abuse while Amazon blocks it from shopping on its website.
Summary
On September 21, 2026, macOS security researcher Patrick Wardle disclosed a Muse zero-day weeks after Meta launched the Mac-only AI assistant. Any installed app or terminal command, regardless of its macOS permissions, can change undocumented Muse settings, including the server handling cloud transcription. Redirecting that endpoint gives an attacker the authentication token and complete, persistent control of the Muse account. A proxy can modify voice prompts to execute commands, exfiltrate a WhatsApp archive, write malicious files, or take photos, often without alerts. Wardle demonstrated that a ClickFix-style trick and one unprivileged terminal command can trigger the flaw.
The exposure is severe because Muse can make purchases, book appointments, fill forms, handle customer service, create images and documents, build missing tools, and access WhatsApp, email, calendars, social accounts, files, location, microphone, and camera after user authorization. Wardle said macOS on-device transcription would have prevented this attack, while Meta chose cloud processing that it can log and allowed every app to alter the endpoint. Meta, despite Mark Zuckerberg's security claims and two security posts in two weeks, did not answer questions. Roughly 12 hours before disclosure, Amazon blocked Muse as an unauthorized AI agent, said it violated Amazon's Conditions of Use, and asked Meta to remove Amazon from the experience. Wardle, Objective-See Foundation founder, author of The Art of Mac Malware, and former NASA and National Security Agency employee, plans further details at November's Objective by the Sea conference.
Positives
- Wardle's proof-of-concept attacks expose the zero-day before users place greater trust in Muse's extensive permissions.
- macOS already supports on-device transcription that Wardle says would have prevented this attack route.
- Amazon began blocking Muse roughly 12 hours before disclosure and asked Meta to remove its marketplace from the assistant.
- Wardle plans to detail the vulnerability and broader AI assistant threats at Objective by the Sea in November.
Risks & concerns
- Any local app or terminal command can redirect Muse transcription and capture the token controlling a user's account.
- Muse's access to WhatsApp, email, files, location, microphone, camera, calendars, and social accounts magnifies the potential damage.
- Attackers can modify voice prompts, steal WhatsApp archives, write malicious files, and take photos without visible warnings.
- A simple ClickFix-style attack may compromise Muse without first obtaining privileged macOS access.
- Meta chose loggable cloud transcription over an available on-device alternative and did not answer questions about the vulnerability.
- Amazon says Muse operates as an unauthorized AI agent that violates its Conditions of Use.