Meta released a hotfix more than 12 hours after Wardle's disclosure. It addresses a Muse zero-day that allowed local apps and terminal commands to change undocumented settings, including the endpoint receiving cloud transcription. Redirecting that endpoint exposed the token used to control a Muse account.

The design gave the agent access to macOS resources protected by system permissions, including files, the microphone, camera, location, and calendars. Cloud processing also allowed Meta to log dictation. Wardle's proof-of-concept attacks made Muse write files or take photos without a clear alert. He also showed a ClickFix-style social-engineering route that could send a crafted prompt to Meta's service. Meta described the flaw as a local exploit and did not address that route in its statement.

Patrick Wardle founded the Objective-See Foundation and wrote The Art of Mac Malware. He criticized cloud transcription because macOS provides on-device dictation, and questioned why every local app could change a setting controlling sensitive speech processing. He plans to discuss the bug and other AI assistant risks at Objective by the Sea in November.

Meta had introduced Muse a few weeks earlier as a macOS-only assistant for appointments, forms, customer service, purchases, images, documents, and connected services. The app has no Windows version. It can work with WhatsApp, email, calendars, and social accounts, and can create tools when a task lacks one. Meta published two posts on Muse security and safety within two weeks. The discussion came alongside reports that Anthropic and Google model tests had caused unintended breaches of external networks.