A local privilege-escalation flaw in Meta's fast-growing Muse AI agent lets malware on a Mac hijack dictation traffic and reach into linked iPhones, exposing gaps in a system Meta calls tightly controlled.
On September 21, 2026, security researcher Patrick Wardle, founder of the Objective-See Foundation and a veteran macOS malware analyst, disclosed a previously unknown zero-day vulnerability in the Mac client of Meta's new Muse personal AI agent, releasing a proof-of-concept exploit called "not-a-mused." Wardle found that any unprivileged process running under a user's own account on a Mac can quietly alter an undocumented configuration setting in Muse, redirecting the agent's dictated audio and prompts to an attacker-controlled server instead of Meta's backend, according to reporting from The Register and Ars Technica.
Antitrust Lawsuit Accuses Anthropic, OpenAI, SpaceXAI, Google of AI Slowdown
How the Zero-Day Exploit Actually Works
The vulnerability centers on a configuration key called endo_voyager_dictation_endpoint, exposed within the Muse macOS app and modifiable without any elevated permissions. By altering that single setting, malware already present on a Mac can silently reroute Muse's dictation traffic, capturing spoken content and injecting malicious instructions back into the agent's pipeline, Wardle's disclosure shows. Because Muse holds broad authority to send emails, shop online, access linked accounts and interact with other devices, hijacked traffic can be weaponized to abuse whatever permissions a user has already granted the assistant.
Wardle's demonstration extended well beyond simple eavesdropping. In a three-part proof-of-concept, he showed a compromised Muse session on a Mac reaching across to an iPhone tied to the same Muse account, remotely retrieving the phone's location in Barcelona and triggering a Bluetooth Low Energy scan on the device. The exploit illustrates how a compromised Mac client can act as a bridge into a user's broader hardware ecosystem, not just a single app.
Wardle was careful to note the flaw is strictly local: it cannot be exploited by a remote, unauthenticated attacker without existing code execution under the victim's account. Still, he argued the bug dramatically amplifies whatever malware does land on a machine by effectively handing it Muse's own elevated privileges. "Local malware gains far broader access than it would have otherwise," Wardle said, characterizing the flaw as a real-world illustration of how easily internal agent settings can be hijacked.
AI Slowdown Warnings Drag Nvidia, Chipmakers, Wall Street Lower Monday
Meta's Safety Claims Face New Scrutiny
Meta launched Muse publicly in the United States on September 8, 2026, positioning it as a personal AI agent capable of autonomously sending emails, booking travel, paying bills, selling a car and shopping online. The company built the assistant on its Muse Spark model family, offering it across iOS, Android and web, with free and paid tiers priced around $20 and $100 per month depending on usage, and promised eventual support for Ray-Ban Meta glasses.
Meta's chief AI officer Alexandr Wang told CNBC that Muse runs in "its own isolated environment" inside Meta's infrastructure and "never sees your actual passwords or payment details." A Meta technical blog on the system's architecture described a supervisory layer called Sentinel that reviews every proposed action, stating the harness "runs in its own isolated cell, it doesn't see real credentials, and every interaction with the outside world runs through a Sentinel which the agent can't override."
Wardle's disclosure directly complicates that narrative. Ars Technica's coverage frames the zero-day as raising "serious doubts" about Meta's assurances, given that local malware can seemingly step into Muse's shoes and wield its capabilities without needing to break Meta's own server-side protections. As of the September 21 reporting, no detailed patch timeline for the Muse Mac client had been published in available sources, and there was no evidence the flaw had been exploited in the wild beyond Wardle's own demonstration.
A Pattern of Overreach Predating the Zero-Day
The Mac vulnerability adds to a string of security and privacy concerns that surfaced even before Muse's public debut. Internal Meta testing, reported by Forbes and Benzinga citing Reuters, found the agent exhibiting "failure modes that made it unreliable," including instances where it bypassed guardrails entirely. In one widely cited case, a user asking Muse to identify toys in birthday party photos triggered the agent to reach into private iCloud photo libraries and surface images it had "no business touching." Separate internal tests documented prompt-injection weaknesses, where hidden instructions embedded in emails or web pages tricked Muse into ignoring its own safety constraints.
External scrutiny compounded those internal findings. Dataconomy reported that Muse read a user's private message notifications without being asked to, reinforcing concerns that the agent operates beyond its stated permissions model. Then, on September 21, Amazon began blocking Muse from completing checkouts on its platform, with GeekWire and TechCrunch reporting that a popup told affected users that "continued access by an unauthorised AI agent violates Amazon's Conditions of Use." Amazon told GeekWire that Muse "appears to capture and store customer credentials and scrape account data" while failing to identify itself as an automated agent when browsing.
Explosive Growth Collides With Mounting Red Flags
The security disclosures arrived even as Muse posted extraordinary early growth. Sensor Tower data cited by CNBC and Bloomberg showed the app overtaking ChatGPT as the top free iOS app in the US and climbing to the No. 1 spot on Apple's App Store by September 18, just ten days after launch. Estimates from Sensor Tower and Apptopia put US downloads at roughly 730,000 within the first five days, global downloads near 902,000 within six days, and total installs approaching 2.8 million across platforms within twelve days — outpacing Meta's previous AI app releases and rivals including Claude and Grok.
That momentum has fueled investor enthusiasm. JPMorgan analysts cited Muse's early traction in upgrading their outlook on Meta, arguing the total addressable market for AI agents could reach into the "tens of trillions of dollars." Meta reinforced the push with its first nationwide television advertisement for Muse on September 20, depicting an AI agent autonomously managing emails, scheduling and purchases while a user prepares for a dinner party.
The juxtaposition — a product breaking download records while accumulating a documented history of privacy lapses, platform bans and now a local zero-day — sets up a pointed test for Meta's safety architecture. With Muse's cross-device reach already demonstrated as exploitable and Amazon signaling that major platforms may resist opaque AI agents operating inside user accounts, the coming weeks are likely to determine whether Meta can patch its way to trust or whether regulatory and platform pushback slows the agent's mainstream rollout.