← DOOMRADAR
cyber · First tracked by DoomRadar:
46DOOM SCORE

Meta patches Muse zero-day that could hijack Mac AI assistant

Meta issued a hotfix for a Muse vulnerability on Mac computers. The flaw could let an attacker redirect dictated audio and exploit permissions already granted to the assistant, although code execution on the victim’s computer was reportedly required first.

By DoomRadar · Published on DoomRadar . Updated .

Based on two sources with available article excerpts. Source-linked claims are not independent confirmation.

What happened

A security researcher said a local process could redirect dictated audio to an attacker’s server, potentially exposing prompts and authentication material and enabling prompt injection. [2]

References for this detail (1)

Context from the sources

Muse was launched as a personal AI agent with access to functions such as email, travel booking, shopping and goal tracking, increasing the significance of permissions attached to the assistant. [1]

Explore the sources and reporting timeline

2 source links · 2 domains

These counts describe the references, not independent confirmations. Different outlets can repeat the same original report.

Source timeline

Oldest to newest among the available source dates, not a chronology of the incident. Article publication dates come from the source; other recorded dates may reflect when a link was found.

  1. Recorded source date: Sep 22, 2026, 3:47 PM UTC[1] Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistantgizmodo.comReferenced for: detail 1, detail 2, detail 4
  2. Recorded source date: Sep 23, 2026, 1:31 AM UTC[2] Security researcher says don't install Meta's Muse AI assistantitnews.com.auReferenced for: detail 3

What this could mean for you

Digital services

Dictated prompts or authentication material could be exposed.

A local process may redirect Muse’s dictation endpoint to an attacker-controlled server.

Reported basis: [1][2] · The possible effect is interpretation.

Depends on: An attacker must first run malicious code on the Mac and the user must be using a vulnerable Muse version.

Safety

Connected assistant functions could be misused.

Hijacking Muse may allow abuse of permissions already granted to the AI agent.

Reported basis: [1][2] · The possible effect is interpretation.

Depends on: The flaw is exploited before the application is patched.

Possible consequences, not a forecast. Their relevance depends on your location and the conditions above.

For your country

Choose a country to check how this event could affect you.

What changes the outlook

Risk increases if…

Evidence that the vulnerability was exploited before users installed the hotfix.

Continued use of an unpatched Muse version on Macs where malicious code can run.

Pressure eases if…

Meta’s hotfix is applied to affected Muse installations.

Independent testing confirms the vulnerable dictation endpoint can no longer be redirected.

Still unclear

The sources do not establish whether attackers exploited the flaw in the wild.

The sources do not specify which Muse versions contain the fix or how many users were affected.

Market implications

Market impact

Loading market analysis...
Sources (2)

References for the reported details. Separate links do not necessarily mean independent confirmation.

[2] Security researcher says don't install Meta's Muse AI assistant ↗itnews.com.au · Recorded source date: Sep 23, 2026, 1:31 AM UTC
Available excerpt
Expert "not-a-mused" by insecure AI agent. Patrick Wardle has published proof-of-concept code for a zero-day, dubbed "not-a-mused", that can turn Meta's Muse AI assistant into…
A short excerpt from our source record; open the original for the full article.

AI-assisted analysis · . Based on linked headlines and available excerpts. Methodology · Report an error.