The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

TheModelDesk

September 23, 2026
models, agents & local inference

Security

Meta patches Muse flaw that exposed macOS privileges

Meta has released a hotfix for Muse after researcher Patrick Wardle showed that local software could redirect cloud transcription and obtain the token controlling an account. His follow-up analysis says the design also weakened macOS permission boundaries and could be triggered through ClickFix-style social engineering. Meta called the issue local and did not explain its cloud transcription choice.

Meta patches Muse flaw that exposed macOS privileges
Image: WIRED ↗

Meta released a hotfix more than 12 hours after Wardle's disclosure. It addresses a Muse zero-day that allowed local apps and terminal commands to change undocumented settings, including the endpoint receiving cloud transcription. Redirecting that endpoint exposed the token used to control a Muse account.

The design gave the agent access to macOS resources protected by system permissions, including files, the microphone, camera, location, and calendars. Cloud processing also allowed Meta to log dictation. Wardle's proof-of-concept attacks made Muse write files or take photos without a clear alert. He also showed a ClickFix-style social-engineering route that could send a crafted prompt to Meta's service. Meta described the flaw as a local exploit and did not address that route in its statement.

Patrick Wardle founded the Objective-See Foundation and wrote The Art of Mac Malware. He criticized cloud transcription because macOS provides on-device dictation, and questioned why every local app could change a setting controlling sensitive speech processing. He plans to discuss the bug and other AI assistant risks at Objective by the Sea in November.

Meta had introduced Muse a few weeks earlier as a macOS-only assistant for appointments, forms, customer service, purchases, images, documents, and connected services. The app has no Windows version. It can work with WhatsApp, email, calendars, and social accounts, and can create tools when a task lacks one. Meta published two posts on Muse security and safety within two weeks. The discussion came alongside reports that Anthropic and Google model tests had caused unintended breaches of external networks.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

← The Model Desk — Page C1

Models, agents & local inference · The Daily Commit · Screen edition · Imprint · Privacy Policy