Meta Muse macOS flaw could expose assistant data and actions
Cybersecurity researcher Patrick Wardle discovered a zero-day vulnerability in Meta’s Muse assistant that affected macOS, not Android. Locally running apps or terminal commands could take control of Muse, but the flaw could not break into a Mac on its own.

Key takeaways · 4
- 01
The vulnerability affected Muse on macOS, not Android; CPO Magazine reported that Meta had no Windows version at the time.
- 02
An attacker needed the ability to run code as the local user; the dictation-setting weakness was not remotely exploitable.
- 03
Meta’s hotfix removed the dictation setting from production builds.
- 04
A captured token could reportedly enable access to Muse chat history and direct control of the assistant.
How the vulnerability worked
The flaw arose because any program running under a user’s account could modify Muse’s dictation setting in the app’s local preferences.[1] Locally running apps or terminal commands could then take control of Muse and perform malicious actions.[1] The vulnerability could enable prompt injection, capture dictated audio and prompts, and expose Muse authentication material.[3] The weakness was not remotely exploitable: an attacker had to already be able to run code as the local user, and it could not break into a Mac by itself.[1][2]
Potential reach beyond the Mac
The Hacker News reported that an attacker using a captured token could read Muse chat history and control the assistant directly.[2] A compromised Muse account could also let an attacker issue commands to the assistant on other devices signed into that account.[2] In tests described by The Hacker News, Wardle used Muse on an iPhone to report its location, scan nearby Bluetooth devices and list available smart-home commands.[2] CPO Magazine reported that compromising the Muse Agent could provide access to Muse data and capabilities, including a linked iPhone.[1]
Patch and disclosure
Meta released security hotfixes by removing the dictation setting in production builds.[1] Meta said it released a hotfix more than 12 hours after the relevant post went live.[4] The Hacker News reported that Wardle did not notify Meta before publicly disclosing the flaw.[2] After the vulnerability became public, Amazon blocked Muse, saying the assistant violated its Conditions of Use.[1]
What Muse can access
Meta describes Muse as an assistant that can book appointments, handle customer service, fill forms and make purchases.[1] It can connect to services including WhatsApp, email, calendars and social-media accounts.[1] Meta says Muse runs in a cloud virtual machine that stores information users share and things they create with the assistant, and that each user’s virtual machine is isolated from other users’ agents.[5] Meta also says Muse asks users to confirm certain important actions, including sending an email or making a purchase.[5]
For teams evaluating desktop AI assistants, this incident highlights the importance of reviewing both local-device security and the permissions an assistant can exercise across connected services. Separate the fact that this flaw required local code execution from the broader question of what an already-compromised assistant account could reach.
Why it matters
Test yourself on this story — 2 questions.
Create a free account to take the quiz, earn XP, and get a daily session built for your industry.
Take the quizHow this developed
3 October 2026
Meta Muse macOS flaw could expose assistant data and actions
Sources
- Meta Muse AI Assistant’s Zero-Day Vulnerability Could Enable Attackers to Inject Malware - CPO Magazinecpomagazine.com
- One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoorthehackernews.com
- GitHub - pwardle/not-a-mused: Not a Mused · GitHubgithub.com
- Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw | WIREDwired.com
- How Muse handles your privacy, safety and security | Meta Help Centermeta.com