Dashboard

Meta Muse macOS Zero-Day Exposes Account Tokens

Patrick Wardle's disclosure is specific to Muse. The shape of the problem, an over-privileged assistant with rewritable settings, is not.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
22 September 20261 min read

Security researcher Patrick Wardle disclosed a zero-day in Meta's Muse assistant for macOS on 21 September 2026. Any unprivileged local process can rewrite an undocumented setting called endo_voyager_dictation_endpoint, redirecting Muse's dictation traffic to a server the attacker controls. What flows to that server includes dictated audio, prompts, and an authentication token that can hand over the victim's Muse account along with everything the user granted the app. No patch has been reported.

How the Meta Muse macOS Zero-Day Works

There is no memory corruption here and no privilege escalation in the traditional sense. The setting is simply writable by code running as the user, and Muse trusts it. Wardle's proof of concept, named not-a-mused, demonstrates that a ClickFix-style social engineering prompt plus a single unprivileged terminal command is enough.

The consequence is broader than eavesdropping. Wardle reports that the proof of concept implements only a subset of more than 50 commands Muse exposes, and that separate demonstrations showed a compromised account enumerating linked devices and directing an online iPhone to return location data or start a Bluetooth Low Energy scan. A flaw on one Mac reaches a phone that was never compromised.

Meta had not publicly responded to the findings when the first reports appeared. The company runs a bug bounty offering up to $300,000 for qualifying Muse security flaws, which tells you how seriously the category is taken internally, not what will happen here.

Zero-day means there is no fix available while the details are public, so the practical position for anyone running Muse on a Mac today is that the flaw is live. Wardle's own recommendation, reported by iTnews, is not to install it. That is a stronger line than most researchers take, and it reflects that the mitigation available to a user is limited: you cannot revoke the setting, only the application's access.

The Structural Problem Behind It

Wardle's framing is the useful one: Muse's broad user-granted permissions let local malware effectively bypass macOS permission separation. The assistant was granted microphone, accessibility, automation and device-linking rights because it needs them to be useful. Malware that hijacks the assistant inherits all of it without ever asking the operating system for anything.

This is the same trade every capable AI assistant makes, and it is not specific to Meta. We made a version of this argument about handing an agent your inbox and about letting one drive your browser. Muse is the clearest illustration so far because the vulnerability is so mundane. A writable settings key did it.

What to Check on Anything You Have Installed

  1. What permissions does it hold? On macOS, System Settings, Privacy and Security, then walk microphone, screen recording, accessibility and automation. Accessibility and automation are the expensive ones.

  2. Does it hold a long-lived credential? An assistant that stays signed in holds a token, and a token is what actually gets stolen. Know where sessions are revoked before you need to revoke one.

  3. Is it linked to other devices? Device linking converts a single-machine compromise into an account compromise. Unlink what you are not using.

  4. Does it phone somewhere configurable? Endpoints that can be pointed elsewhere by local configuration are the exact class of thing this disclosure is about.

None of that is a reason to uninstall every assistant, and Wardle's own recommendation for Muse specifically is more cautious than mine. It is a reason to notice that these tools are among the most privileged software on a typical machine while being reviewed like a note-taking app. That gap is the actual risk, and it belongs on the same shelf as the other AI risks worth tracking. Muse's earlier appearance here was a model release, which is a fair summary of how quickly the surface has grown.

Sources: Mallory's write-up of the disclosure and iTnews reporting on Wardle's recommendation, both 21 September 2026.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.