Skip to main content

Meta Muse macOS flaw could expose assistant data and actions

3 OCTOBER 2026·2 MIN READ·5 SOURCES

Cybersecurity researcher Patrick Wardle discovered a zero-day vulnerability in Meta’s Muse assistant that affected macOS, not Android. Locally running apps or terminal commands could take control of Muse, but the flaw could not break into a Mac on its own.

Meta Muse macOS flaw could expose assistant data and actions

Key takeaways · 4

  • 01

    The vulnerability affected Muse on macOS, not Android; CPO Magazine reported that Meta had no Windows version at the time.

  • 02

    An attacker needed the ability to run code as the local user; the dictation-setting weakness was not remotely exploitable.

  • 03

    Meta’s hotfix removed the dictation setting from production builds.

  • 04

    A captured token could reportedly enable access to Muse chat history and direct control of the assistant.

How the vulnerability worked

The flaw arose because any program running under a user’s account could modify Muse’s dictation setting in the app’s local preferences.[1] Locally running apps or terminal commands could then take control of Muse and perform malicious actions.[1] The vulnerability could enable prompt injection, capture dictated audio and prompts, and expose Muse authentication material.[3] The weakness was not remotely exploitable: an attacker had to already be able to run code as the local user, and it could not break into a Mac by itself.[1][2]

Potential reach beyond the Mac

The Hacker News reported that an attacker using a captured token could read Muse chat history and control the assistant directly.[2] A compromised Muse account could also let an attacker issue commands to the assistant on other devices signed into that account.[2] In tests described by The Hacker News, Wardle used Muse on an iPhone to report its location, scan nearby Bluetooth devices and list available smart-home commands.[2] CPO Magazine reported that compromising the Muse Agent could provide access to Muse data and capabilities, including a linked iPhone.[1]

Patch and disclosure

Meta released security hotfixes by removing the dictation setting in production builds.[1] Meta said it released a hotfix more than 12 hours after the relevant post went live.[4] The Hacker News reported that Wardle did not notify Meta before publicly disclosing the flaw.[2] After the vulnerability became public, Amazon blocked Muse, saying the assistant violated its Conditions of Use.[1]

What Muse can access

Meta describes Muse as an assistant that can book appointments, handle customer service, fill forms and make purchases.[1] It can connect to services including WhatsApp, email, calendars and social-media accounts.[1] Meta says Muse runs in a cloud virtual machine that stores information users share and things they create with the assistant, and that each user’s virtual machine is isolated from other users’ agents.[5] Meta also says Muse asks users to confirm certain important actions, including sending an email or making a purchase.[5]

For teams evaluating desktop AI assistants, this incident highlights the importance of reviewing both local-device security and the permissions an assistant can exercise across connected services. Separate the fact that this flaw required local code execution from the broader question of what an already-compromised assistant account could reach.

Why it matters
Story quiz

Test yourself on this story — 2 questions.

Create a free account to take the quiz, earn XP, and get a daily session built for your industry.

Take the quiz

How this developed

  1. 3 October 2026

    Meta Muse macOS flaw could expose assistant data and actions

Sources

AI fluency, one session a day, built for your work.