Guide 21 · Safety

The Muse Mac Security Flaw: What Actually Happened

A researcher found a serious Mac app flaw; Meta patched it within a day. The full timeline and what it means for you.

By Abhit T. · Updated October 6, 2026 · 8 min read

Short answer

On September 21, 2026, researcher Patrick Wardle disclosed a zero-day in the Muse Mac app that could let local malware hijack the agent; Meta issued a hotfix on September 22. Keep the app updated.

Editorial illustration of a magnifying glass over a laptop revealing a cracked padlock
Illustration: museaicodes

The timeline

September 21, 2026: macOS security researcher Patrick Wardle published an X thread warning users about serious flaws in the Muse Mac app, alongside a proof-of-concept repository he titled 'not-a-mused.' His opening line: 'Please don't install — it's trivial to turn Muse into the ultimate backdoor.'

September 22, 2026: Wardle posted 'Hooray, hot-fixed!' confirming Meta had patched the vulnerability — roughly a day after disclosure. David Singleton of Meta Superintelligence Labs confirmed the hotfix on X, describing the issue as a local privilege escalation attack, not a remote exploit, and assessing the practical risk to users as 'quite low.'

What the flaw was

The vulnerability centered on an undocumented preference setting in the Mac app — endo_voyager_dictation_endpoint — which controlled where Muse sent voice dictation for processing. Any app or script running under the user's account could modify this setting without triggering macOS permission alerts, redirecting transcription from Meta's servers to an attacker's endpoint.

That redirection exposed the user's account authentication token. With the token, an attacker gained full control of the agent — and because Muse holds broad system permissions by design, Wardle's proof of concept could take pictures and write malicious files to disk, often without alerting the user. As he told Ars Technica: 'We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.'

Several design choices enabled it: dictation processed in the cloud rather than on-device (unlike Apple's on-device transcription), and undocumented settings left writable by any local process.

How serious was it, really

Two things are true at once. The exploit required local code execution — malware already running on the machine, physical access, or a social-engineering trick like a ClickFix prompt getting the user to paste a terminal command. It was not remotely exploitable over the internet, which is why Meta assessed real-world risk as low.

But the deeper point stands: an agent designed to act across your files, email, messages, and calendar with broad permissions becomes the single highest-value target on the machine. Compromise the agent and you inherit everything it can touch. That structural reality doesn't disappear with one hotfix — it's the permanent trade-off of computer-use agents. Our privacy guide answers what Muse can see and what you can opt out of.

What to do as a user

  • Update the Muse Mac app and keep it updated — this is how security fixes reach you.
  • Never paste terminal commands from strangers, popups, or videos. ClickFix-style tricks are the cheapest attack path.
  • Keep macOS itself updated; OS-level protections are part of the defense.
  • Grant Muse the narrowest permissions each task needs, and revoke access you no longer use.
  • Treat any agent with deep system access as high-trust software: powerful, useful, and worth a skeptical eye.

The bigger picture

This episode landed in a week when platforms started pushing back on autonomous agents more broadly — Amazon began blocking Muse from placing automated orders, saying the agent violated its terms. The industry is negotiating, in real time, what agents are allowed to do and who is responsible when they do it.

Our honest take: Muse's capabilities are real, and so are the risks that come with an agent holding your credentials and permissions. Use it, but grant least privilege, keep everything updated, and remember that the most powerful assistant on your machine is also the most attractive target on it.