← News

Researcher discloses Meta Muse macOS zero-day

macOS security researcher Patrick Wardle disclosed a zero-day in Meta’s Muse assistant that lets any local app or terminal command rewrite an undocumented dictation-endpoint setting, redirect voice prompts to an attacker server, and obtain the token that controls the Muse account — including leverage over linked devices.

SAFETY desk — personal AI agents with root-like access to your life raise the cost of a single local bug from “steal one app” to “own the assistant that already has the keys.”

What the flaw is, at the level Ars reports. Muse keeps a list of settings that are not in the public menus. Any app already on the Mac, or any code the person runs, can change those settings, even when that app lacks the special macOS permissions Apple uses to guard the microphone, the camera, and files. Most of the settings are ordinary. Ars gives dark mode as the harmless example. One setting is not harmless. It holds the server address where Muse sends speech to be turned into text. That job is called transcription, or dictation. The normal address belongs to Meta. Someone who can change it can point the address at a server they control. This path starts with code already running on the Mac. It is not a remote break-in of a machine where nothing local has run.

What Ars says happens after that address changes. Once the person dictates, the other server receives the token that signs the user in to Muse. A token, here, is the credential that says this session may act as that Muse account. Ars says that token gives complete control of the account. The leverage is the access the person already granted the assistant, not a new remote hole. Ars lists that access as files on the Mac, the microphone and camera, and connections such as WhatsApp, email, calendar, and social accounts. Controlling the account is also the stake the disclosure describes for devices already tied to that same Muse login. This filing does not list device commands.

Wardle’s line, quoted by Ars: “We can manipulate the agent and leverage its privileges to do whatever we want.” He told Ars that an attacker can use the assistant itself instead of writing a full Mac stealer. A stealer is malware whose job is to copy secrets off the computer. He also told Ars he had built demonstrations that do things such as writing files and taking pictures, in many cases with no alert even a careful user would see. File the quote and those outcomes as his, via Ars. Outcomes are not steps. This filing does not include a command, a setting name, or a reproduction recipe.

How the first foothold can arrive, still high level. Ars says a ClickFix-style lure can be enough. ClickFix is a social-engineering trick: a page or a message talks a person into running something on their own computer. It is not an attack that fires by itself when someone only looks at a page. File that path as Ars’s. The lure and the command stay out of this card.

Meta did not answer. Ars says Meta representatives did not answer emailed questions. This desk does not have a Meta confirmation, a patch note, or a public vulnerability number. Do not invent a fix. Do not invent a statement that Meta agreed the bug is real. Silence is not a confirmation, and it is not a denial this desk can quote.

Wardle published a proof-of-concept repository on GitHub under the name not-a-mused. A proof of concept is a demonstration that a flaw is real. This filing cites that repository as his disclosure vehicle. It does not reprint what is inside it. Ars describes Wardle as the founder of the Objective-See Foundation, a nonprofit focused on macOS security, a former employee of NASA and the National Security Agency, and the author of The Art of Mac Malware. He told Ars he plans to discuss the vulnerability, and other threats to AI assistants, at the Objective by the Sea conference in November. File that biography as Ars’s.

One design point Wardle gave Ars, still not a how-to. Muse sends dictation to the cloud, where Meta can log it, instead of using the on-device transcription macOS already provides for apps. He said that cloud choice is what made a redirected address possible. He also said letting any local app change the whole hidden list looks like a door meant for harmless interface options, not for the server that receives someone’s speech. File those design lines as his, via Ars. They explain the shape of the flaw. They are not instructions.

Do not fold this into Amazon’s block of Muse shopping. That is a retailer shutting an agent out of a store. Ars notes the block began around the same day. It is a different story, already filed on this desk. Do not read this card as a remote, unauthenticated compromise. Do not treat a demonstration as evidence the flaw is being used in the wild. Ars does not establish that. A finished patch would be a Meta note or a software update. None is on this card.

Plain English for the rest of the card: zero-day = a flaw still open when it is disclosed. Muse = Meta’s personal AI assistant for macOS. AI agent = software that can take steps, not only chat. dictation / transcription = turning speech into text. endpoint = the server address that receives that speech. token = the credential that lets a session act as the Muse account. ClickFix = a lure that gets a person to run something on their own computer. stealer = malware that copies secrets. local code = an app or a command already running on that Mac. This filing is Wardle’s disclosure as Ars reported it. It is not a patch, and it is not the Amazon shopping block.

REPORTED here: Ars Technica’s 21 Sep 2026 article by Dan Goodin — Tier B same-day specialist press, not a Meta newsroom and not a patch note — plus Wardle’s public not-a-mused repository as the researcher’s own disclosure vehicle. The local zero-day, the undocumented settings any local app or executed code can change, the dictation-endpoint address, the token on dictate, complete control of the Muse account, the file / microphone / camera / WhatsApp / email / calendar access, the stealer quote, the file-and-picture outcomes, the ClickFix-style foothold, Meta’s silence, the cloud-dictation design line, and the Objective-See biography are Ars-attributed to Wardle or to Meta’s non-response. The repository name is the public disclosure vehicle. NOT claimed: remote unauthenticated compromise, a Meta confirmation, a patch, a vulnerability number, in-the-wild use, that this desk ran a demonstration or reprinted commands, a stock tip, or investment advice. Distinct from the already-filed amazon-blocks-meta-muse, amazon-perplexity-amended-complaint, and un-ai-panel-agents.

RELATED

ONLINE

article thread

guidelines

warming…

warming…

On 21 Sep 2026, Ars Technica’s Dan Goodin reported that Patrick Wardle had disclosed a zero-day in Meta’s Muse app for macOS. A zero-day is a flaw the maker has not patched, described in public while it is still open. Muse is Meta’s personal AI assistant. An AI agent, here, is software that can take steps for a person — book, buy, message — not only answer a chat. These lines are Ars’s account of Wardle’s disclosure. This desk did not run a demonstration.

Sources