Meta Patches Mac Muse Flaw That Enabled Local Agent Takeover

Meta has patched a zero-day flaw in its Muse app for macOS that allowed takeover of the AI agent. A zero-day is a flaw that was being fixed after it became publicly known, with no prior patch available. The flaw was found by security researcher Patrick Wardle and made public in an Ars Technica report on Sept. 21, 2026. Meta shipped a hotfix within hours, according to reporting on Sept. 22. The Verge
The problem centered on voice transcription and hidden settings. Muse processed dictation in the cloud rather than on the device. An attacker with code already running locally could use an undocumented Muse setting, a control built into the software but not shown to users, to redirect that transcription work from Meta's servers to an attacker-controlled server. Any local app could change all of Muse's undocumented settings, which gave a direct path from local code to control over agent behavior.
That starting condition matters. Exploitation required malicious code already running on the user's Mac under the user's account. It was not a remote network exploit. Wardle also said the Muse agent could be hijacked through a simple ClickFix-style attack, a technique that tricks a user into running attacker-supplied steps on their own machine. Cybernews
Once that local foothold existed, the impact was broad. Successful exploitation gave the attacker access to the victim's Muse account. In proof-of-concept tests, Wardle used Muse to take pictures and write malicious files to disk, in many cases without alerting the user.
Meta framed the severity in narrow terms. Superintelligence Labs executive David Singleton described it as a "local privilege escalation attack," meaning code with basic local access could gain wider control, and said the practical risk to users was "quite low" because remote exploitation was not involved. The fast hotfix closed the transcription-redirect path and locked down the settings surface.
Two separate developments arrived alongside the patch news. Amazon blocked the Muse AI agent from Amazon's e-commerce platform, saying Meta never obtained permission for that access. Separately, estimated downloads of the Muse mobile app in its first 12 days reportedly outpaced ChatGPT's 12-day debut in the US and Canada.
The broader context here is architectural, not only about a single bug. A highly privileged agent that can act on files, camera input, and account-linked services takes on the security limits of its weakest part. In this case that included cloud-routed dictation, changeable hidden settings open to other local processes, and account access that persisted after compromise. Local code execution is often treated as game over in endpoint security, but agent frameworks raise the cost because one local compromise can become lasting account access and unattended actions.
Looking at what this means for agent builders, the fixes point in clear directions. Undocumented controls need the same access limits and audit logging as public controls. Cloud fallback for sensitive functions such as transcription needs endpoint pinning and integrity checks, checks that lock the connection to the correct server, not routing the client can change. And user consent needs to match the actual action, especially when the agent can write files or capture media without a visible prompt. In my view, the speed of this patch is encouraging, and the long-term gain is a more robust pattern for agentic apps on desktop systems where many processes share the same user.


