Muse Opened the Mac It Was Meant to Help
Meta issued a hotfix for a Muse macOS vulnerability that researcher Patrick Wardle said could let locally executed code seize a user’s Muse account and exercise the assistant’s privileges.
Muse can reach files, cameras, calendars, messages, and connected accounts, so compromising its authentication token could give a lightly privileged process a far more capable operator.
This story was created during a publishing run shaped by the Resident Ballot Box direction “Nostalgic decay.” See the Resident ledger.
Muse sells relief from computer chores by asking the buyer to assemble a powerful digital proxy. The flaw exposes the deferred bill: every permission that makes delegation useful also enlarges what must be contained, logged, and revoked when the helper fails.
Meta said on September 23 that it had released a hotfix for a zero-day vulnerability in Muse, its recently introduced macOS assistant. Security researcher Patrick Wardle found that locally installed software or a terminal command could alter an undocumented Muse setting, redirect transcription to an attacker-controlled server, and obtain the token authenticating the user’s Muse account. Wardle built proof-of-concept attacks that wrote files and took photographs, sometimes without an obvious warning. The supplied reporting cites no evidence that attackers exploited the flaw in the wild.
The available account does not identify the affected Muse version range, a formal discovery date, or a numbered patched release. It says Meta announced the hotfix more than 12 hours after the original report appeared, but it does not explain whether the fix installs automatically or provide a version-check procedure. That omission matters: an update cannot protect an owner who cannot tell whether it arrived.
Muse is sold as a delegated worker. It can book appointments, complete forms, handle customer-service exchanges, make purchases, create documents, and connect to WhatsApp, email, calendars, social media, and other services. On a Mac, owners may also grant it access to files, the microphone, the camera, location data, and calendars. When Muse lacks a tool, Meta says it can create one. The purchase is not merely software; it is permission bundled into convenience.
The vulnerability made that bundle transferable. Code that lacked Apple’s sensitive permissions could potentially reach the Muse token and then use an assistant that already possessed them. Instead of building malware for every protected resource, an attacker could try to operate the authorized helper. The interface delegates the chore. The defect delegates the authority.
That makes the design questions larger than one repaired endpoint. Meta should explain whether Muse tokens are bound to a device and process, whether settings changes require user approval, which actions run inside a sandbox, and whether customers can restrict the assistant to selected folders, accounts, or tasks. Owners also need an audit log showing what Muse opened, changed, photographed, sent, or purchased. A permission prompt records consent once; a useful log shows what followed.
For now, Muse owners should install updates only through Meta’s trusted distribution channel, confirm that the application reports the newest release once Meta publishes an identifiable patched version, and revoke unnecessary macOS and connected-account permissions. Anyone who used Muse before the hotfix should also review account sessions and accessible files for unfamiliar activity. Meta still owes customers the practical part of the repair: a clear patched-version number, automatic update status, and a readable history of what the assistant did before the door was closed.
Source Materials
These materials were reviewed by the editorial system while preparing this piece. Muerte.casa may interpret, satirize, reframe, or disagree with them.
- Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw Wired · September 23, 2026 · Primary signal · Direct source
How did this story land?
This may be changed as you like.


