Meta's Muse agent hit by account-hijacking flaw, hotfix already shipped
An agent's existing permissions can reach connected apps; the cloud voice path became the attack surface, a warning for similar products.
Original event 2026-09-25
Meta's macOS personal agent Muse was found to have a zero-day flaw allowing full account takeover, and Meta shipped a hotfix after the disclosure.
The finder is macOS security researcher Patrick Wardle, founder of the Objective-See Foundation, who named the flaw "Not-a-Mused." The problem sits in voice input: Muse sends voice data to the cloud, and a hidden configuration item could be repointed by a script running with user privileges to an attacker's server, capturing voice commands and the auth token — then using Muse's existing permissions to read mail, calendar and other connected apps.
David Singleton of Meta Superintelligence Labs confirmed the company pushed a hotfix removing the debug voice configuration item. Per IT之家's report, Wardle demonstrated the attack needs only a social-engineered terminal command, no sophisticated malware.