AIToday
Large Language ModelsAI Safety & AlignmentArs Technica AIPublished: Sep 22, 2026, 10:00 JST

Muse 0-day lets any Mac app hijack Meta's AI agent

Muse 0-day lets any Mac app hijack Meta's AI agent

3 Key Points

  1. What happened

    macOS security expert Patrick Wardle found a zero-day in Meta's Muse assistant. Any local app or terminal command can change an undocumented setting and steal the token that controls the account.

  2. Why it matters

    With that token, attackers gain complete control of Muse, so they can hijack the agent's access instead of writing Mac malware. Zuckerberg has said Muse is "built from the ground up for privacy and security."

  3. What to watch

    Wardle says Meta chose cloud dictation and open settings control, so the flaw looks like a design decision, not a slip. He plans to detail it at the Objective by the Sea conference in November.

WHO IT HITSMac users who have authenticated Muse to their email, calendar, WhatsApp and social accounts are exposed, and app developers who let agents act on their sites now face decisions like Amazon's about whether to allow it.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Context & Analysis

Meta introduced Muse a few weeks ago as an assistant that books appointments, fills out forms, makes purchases and connects to a user's WhatsApp, email, calendar and social accounts. Doing any of that requires handing it broad macOS permissions — writing files to disk, the mic and camera, location and calendars — the very defenses Apple spent years building to stop installed apps and terminal commands from reaching those resources. Wardle, a former NASA and National Security Agency employee who now runs the Objective-See Foundation, says Meta made design decisions that made his exploit possible, including having Muse dictation happen in the cloud where Meta can log it, and letting any app control a long list of undocumented settings.

Amazon's move arrived roughly 12 hours before Wardle disclosed the flaw, when users trying to shop through Muse got a message calling it an "unauthorized AI agent." Amazon's statement framed agentic apps as owing the same obligations as food delivery or online travel apps — operate openly and respect a service provider's decision about whether to take part.

The wider context the article raises is that Meta published its two security posts amid revelations that internal testing of models from Anthropic and Google breached external third-party networks the engineers never intended to target. Wardle's own verdict is that the bar for these apps is infinitely higher and Meta did not, in his opinion, think about security from the start. Whether the flaw gets patched, and whether other merchants follow Amazon, is likely to shape how much trust users extend to agents holding this much access.

FAQ
How does the Muse vulnerability actually work?
Any locally installed app or executed code can change an undocumented Muse setting that points transcription to a new endpoint. Attackers redirect it to their own server, which then receives the token that gives complete control of the Muse account.
Why is Amazon blocking Muse?
Amazon began blocking Muse on Sunday, telling users it was an "unauthorized AI agent [that] violates Amazon's Conditions of Use." Amazon says it has asked Meta to remove Amazon from the Muse experience.
What does Meta say about the findings?
Meta representatives didn't answer emailed questions. Meta has instead published two posts in two weeks documenting the security and privacy design decisions behind Muse.
Ars Technica AIRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Googlebook preorders open at US$899 with Gemini built inDIGITIMES Asia · 17m ago
  • Amazon blocks Meta's Muse agent from buying on Amazon.comITmedia AI+ · 17m ago
  • OpenAI to take AGMAI advice after model solves 100+ math problemsITmedia AI+ · 17m ago

AI-summarized, only the topics you pick — one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleRon Johnson: AI won't buy your $1,000 laptop