New Horizon

Objective-See's Patrick Wardle disclosed a flaw that hands locally run apps or a single terminal command complete control of Muse, weeks after Meta launched it promising security.
Generated via ComfyUI / Z-Image Turbo

One undocumented setting, full account takeover

Patrick Wardle, founder of the macOS security nonprofit Objective-See, disclosed the zero-day this week, according to ithinkdiff.com, which credits arstechnica.com with the underlying reporting. The flaw lets any locally running application, or a single terminal command, take complete control of Muse on the Mac. There is no exploit chain and no privilege escalation: a process already on the machine assumes the agent's authority directly. The disclosure landed weeks after Muse's launch.

The mechanism, per ithinkdiff.com, is one undocumented setting in the Muse app, and that setting opens the door to full account takeover. The report describes the flaw as undoing years of permission protections Apple built into macOS specifically to stop this kind of access — the consent gates that normally require a user to approve one application reaching into another's protected data. Muse bypasses them without a prompt.

The severity follows from the target. cybersecuritynews.com reports the vulnerability allows attackers to hijack the tool and inject malware. theregister.com adds that local malware can redirect dictation traffic, which puts voice prompts — the raw material of a user's instructions to the agent — in reach of whatever process sits on the same machine. A single undocumented setting, in that reading, converts the operating system's consent model into a formality.

What Muse can do, and what the flaw exposes

Muse launched earlier this month in the United States, open to users 18 and older, and runs on Mac, iPhone, Android, and the web. Its stated capabilities are broad: it books appointments, fills out forms, sends emails, manages calendars, and makes purchases using a linked Stripe card. It also generates images, creates documents, and connects with a user's favorite apps and services, per the launch description carried by arstechnica.com.

Mark Zuckerberg has promoted the assistant as "built from the ground up for privacy and security," a claim arstechnica.com sets directly against the zero-day. ithinkdiff.com frames the stakes the same way: Muse is positioned as an agent trusted to handle a person's email, WhatsApp, calendar, and shopping. The marketing promise and the attack surface describe the same product, and the flaw shows which description the architecture currently supports.

The open question is privilege isolation. An agent that can spend money and send mail is only as safe as the boundary between it and every other process on the host; the Wardle finding indicates that boundary does not hold on macOS. That suggests the problem is architectural rather than a single defective line of code — one setting governs whether local software inherits the agent's full authority.

Amazon blocks Muse as disclosure lands

Amazon on Sunday began blocking Muse from its site, according to arstechnica.com. theregister.com separately reported that Amazon has shown Meta's Muse shopping agent the door. The timing is tight: the Register's coverage ran on Monday 21 September 2026, and Wardle's disclosure circulated the same window, meaning the block landed as the flaw became public rather than after any documented remediation by Meta.

The block matters commercially because Muse makes purchases. A shopping agent cut off from one of the largest retailers loses a primary transaction surface, and the exclusion signals how platforms may treat agents whose security posture is under active question. The record does not state Amazon's reason for the block; both outlets report the action itself and leave the motive unstated.

Two signals are worth tracking. First, whether Meta ships a patch that closes or documents the setting Wardle identified — no timeline appears in the record. Second, whether other retailers follow Amazon's exclusion, which would test whether agent access to commerce is granted per-platform or treated as a default right. The zero-day gives both decisions a concrete technical anchor. Wardle's disclosure stands as the only public technical account of the flaw so far.

Sources


Zero-day Meta Muse Has Serious Any Local AI Tools & Ecosystem

Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.


← All Posts Daily Digest →

The AI news that matters — in your inbox by 07:30 CET. Free, no spam.