Meta's Muse, a new Mac AI assistant that launched to strong early adoption, passed 2.5 million downloads in its first 13 days. On day 21, Mac security researcher Patrick Wardle disclosed a zero-day letting any unprivileged local process hijack the agent entirely, no special macOS permissions required.
Meta patched it within about a day. That's the fast-moving part of this story. The slower-moving part, according to follow-up reporting, is that fixing this one bug didn't fix the deeper visibility gap it exposed.
How the Flaw Worked
Muse processes voice dictation by sending it to a Meta server for transcription. Wardle found that an undocumented setting controlling that server's address, called dictationUrl, could be changed by any locally running process, malware, a malicious app, or a terminal command, regardless of what permissions that process itself had been granted. Redirect that setting to a server you control, and you capture two things at once: the user's dictated voice prompts, and the authentication token that controls their entire Muse account.
Once an attacker has that token, they inherit whatever access the real user had already approved. Wardle's proof of concept, which he named "Not a Mused," demonstrated writing files to disk and taking photos without any warning to the user, and separately obtained the location of a linked iPhone in Barcelona and triggered a Bluetooth scan from it. Since Muse can connect to services including WhatsApp, email, calendars, social platforms, and shopping, a hijacked session isn't limited to the Mac itself.
The Fast Fix
To Meta's credit, the response was quick. The vulnerable setting was removed from production builds roughly a day after disclosure, and Wardle confirmed the patch closed the hole. Amazon, separately, moved the same day to block Muse from being able to make purchases on its site, an early sign that other platforms are treating agentic AI assistants as a distinct trust category rather than assuming a big brand name is enough of a safeguard on its own.
The Part That Didn't Get Fixed
VentureBeat's follow-up reporting raises the more durable concern: even with this specific bug closed, enterprise security teams still have no central visibility into what a deployed AI agent like Muse can actually access. Meta's architecture does include real safeguards, a dedicated virtual machine per account, credentials stored outside the agent's own runtime environment, and a host-side approval process for connector actions, but none of that adds up to the kind of centralized oversight a security team would have over, say, employee laptops or a managed SaaS deployment.
That gap matters more as these agents accumulate permissions. OWASP's list of major AI agent security risks, prompt injection, tool abuse, privilege escalation, data exfiltration, excessive autonomy, memory poisoning, and sensitive-data exposure, reads like a checklist this single incident partially satisfied on its own. The specific bug is patched. The category of risk isn't.
What This Means If You're Evaluating Agentic AI Tools
- Treat any AI agent with broad connected-service permissions, email, calendar, shopping, messaging, as a meaningfully higher-risk deployment than a standalone chatbot, and evaluate it with that higher bar in mind.
- Ask your vendor directly whether your security team gets centralized visibility into what a deployed agent can access and has accessed, not just whether the vendor has internal safeguards. This incident shows those aren't the same question.
- A fast patch is a good sign, but it addresses one exploit, not the underlying risk category. Don't treat a fast fix as evidence the architecture is sound, treat it as evidence the vendor responds quickly when caught.
- If a new agentic AI tool is spreading fast in your organization on its own, unofficially, this is a useful reminder of why that's worth getting ahead of rather than discovering after the fact.
Sources: AI Pulse · Where This Breaks · workplaceai.ai. Patrick Wardle's disclosure and proof of concept, September 21-22, 2026: Ars Technica, Malwarebytes Labs, Digital Trends, and Yahoo Tech. Meta's response and enterprise visibility gap: VentureBeat, September 22, 2026. Amazon's response: Yahoo Tech. OWASP's AI agent risk categories: Malwarebytes Labs, citing OWASP. Every figure and detail above is attributed to its original reporting; none is a WorkplaceAI study.