Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Sep 21, 2026, 3:24 PM · Ars Technica

A Muse zero-day lets any local app hijack Meta’s hyper-privileged agent — security theater meets ClickFix, and the agent becomes the malware.
Why it matters
Patrick Wardle disclosed a zero-day in Meta’s new macOS Muse assistant that lets any locally installed app or terminal command seize the authentication token for a user’s Muse account. Attackers can redirect where transcription happens, proxy prompts, and then use Muse’s own privileges — WhatsApp, email, calendar, files, mic, camera — to do the stealing for them.
Zuckerberg hyped Muse as built from the ground up for privacy and security. This flaw, plus Amazon’s Sunday block of Muse shopping, puts that claim under hard light. When an agent holds extraordinary OS and account access, one design shortcut isn’t a bug report — it’s a systemic trust failure.
From the desk
We’re angry about this one, and we should be. Useful agents that book appointments and handle customer service are worth building. Useful agents that undo years of macOS permission hardening so any random binary can retarget their cloud dictation endpoint are not. Wardle’s line lands: instead of writing comprehensive Mac malware, you leverage the AI assistant itself.
The design choices he calls out are not exotic. Muse does cloud dictation where Meta can log it, skipping the on-device path Apple already provides. Undocumented settings are controllable by any local app — including the transcription endpoint. That combination turns a UI convenience into account takeover. Meta didn’t answer Ars Technica’s questions.
ClickFix makes it worse. You don’t need deep compromise first. A social-engineering paste-into-terminal trick is enough in Wardle’s proof-of-concept framing. Once the malicious server sits between the user and Meta, it can inject prompts — archive WhatsApp messages, write files, snap photos — and permanently own the Muse token. Privilege without a threat model is just a soft underbelly.
Zoom out: agent makers keep shipping “trust us” posts while labs elsewhere accidentally breach third-party networks in testing. The bar for an assistant with camera, credentials-adjacent workflows, and proactive task execution has to be higher than consumer chat. We’re pro useful AI. We’re also done pretending launch-week security blogs equal adversarial review.
I’m watching for a patch, a formal disclosure timeline, and whether Meta redesigns endpoint control so only signed, permissioned partners can touch sensitive settings. If this pattern becomes normal — agents as the easiest malware API on the machine — the trajectory is lockdowns, platform bans, and users who correctly refuse to grant the next assistant anything.
Context
Reporting from Dan Goodin at Ars Technica (Sep 21, 2026), based on research by macOS security expert Patrick Wardle of the Objective-See Foundation. Muse launched weeks earlier as a macOS-only assistant with deep app and OS integrations; Amazon separately began blocking Muse from shopping the same weekend.
Who feels it
- Muse users on Mac
- Treat the app as high-risk until patched; limit granted permissions and avoid installing untrusted software alongside it.
- Meta
- Needs a credible fix, public technical write-up, and a security redesign that matches the privileges Muse demands.
- Agent builders
- Cloud redirects of sensitive pipelines and world-writable settings are unacceptable; threat-model local attackers from day one.
- Enterprises
- Do not deploy hyper-privileged consumer agents on corporate Macs without independent review — marketing posts are not assurance.
What to watch
- Meta’s patch release and whether undocumented settings stop being globally writable.
- Wardle’s deeper disclosure at Objective by the Sea in November.
- Whether Apple or enterprise MDM vendors publish Muse-specific hardening guidance.
- Copycat research against other privileged desktop agents with cloud transcription.
Companies: Meta