Meta patches Muse zero-day that could hijack Mac AI assistant
Meta issued a hotfix for a Muse vulnerability on Mac computers. The flaw could let an attacker redirect dictated audio and exploit permissions already granted to the assistant, although code execution on the victim’s computer was reportedly required first.
By DoomRadar · Published on DoomRadar . Updated .
Based on two sources with available article excerpts. Source-linked claims are not independent confirmation.
What happened
Meta issued a hotfix for a zero-day vulnerability in its Muse AI assistant for Mac computers, according to David Singleton of Meta Superintelligence Labs. [1]
References for this detail (1)
- Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistantgizmodo.com · Recorded source date: Sep 22, 2026, 3:47 PM UTC
The vulnerability involved Muse’s dictation feature, which sends audio to Meta’s servers for transcription instead of processing it locally. [1]
References for this detail (1)
- Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistantgizmodo.com · Recorded source date: Sep 22, 2026, 3:47 PM UTC
A security researcher said a local process could redirect dictated audio to an attacker’s server, potentially exposing prompts and authentication material and enabling prompt injection. [2]
References for this detail (1)
- Security researcher says don't install Meta's Muse AI assistantitnews.com.au · Recorded source date: Sep 23, 2026, 1:31 AM UTC
Meta said an attacker would first need to get malicious code running on the victim’s computer. [1]
References for this detail (1)
- Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistantgizmodo.com · Recorded source date: Sep 22, 2026, 3:47 PM UTC
Context from the sources
Muse was launched as a personal AI agent with access to functions such as email, travel booking, shopping and goal tracking, increasing the significance of permissions attached to the assistant. [1]
Explore the sources and reporting timeline
2 source links · 2 domains
These counts describe the references, not independent confirmations. Different outlets can repeat the same original report.
Source timeline
Oldest to newest among the available source dates, not a chronology of the incident. Article publication dates come from the source; other recorded dates may reflect when a link was found.
- [1] Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistantgizmodo.comReferenced for: detail 1, detail 2, detail 4
- [2] Security researcher says don't install Meta's Muse AI assistantitnews.com.auReferenced for: detail 3
What this could mean for you
Dictated prompts or authentication material could be exposed.
A local process may redirect Muse’s dictation endpoint to an attacker-controlled server.
Reported basis: [1][2] · The possible effect is interpretation.
Depends on: An attacker must first run malicious code on the Mac and the user must be using a vulnerable Muse version.
Connected assistant functions could be misused.
Hijacking Muse may allow abuse of permissions already granted to the AI agent.
Reported basis: [1][2] · The possible effect is interpretation.
Depends on: The flaw is exploited before the application is patched.
Possible consequences, not a forecast. Their relevance depends on your location and the conditions above.
For your country
Choose a country to check how this event could affect you.
What changes the outlook
Risk increases if…
Evidence that the vulnerability was exploited before users installed the hotfix.
Continued use of an unpatched Muse version on Macs where malicious code can run.
Pressure eases if…
Meta’s hotfix is applied to affected Muse installations.
Independent testing confirms the vulnerable dictation endpoint can no longer be redirected.
Still unclear
The sources do not establish whether attackers exploited the flaw in the wild.
The sources do not specify which Muse versions contain the fix or how many users were affected.
Market implications
Market impact
Sources (2)
References for the reported details. Separate links do not necessarily mean independent confirmation.
Available excerpt
Meta’s do-it-all AI assistant Muse launched two weeks ago, and the company has already had to patch a pretty serious zero-day vulnerability in its app…A short excerpt from our source record; open the original for the full article.
Available excerpt
Expert "not-a-mused" by insecure AI agent. Patrick Wardle has published proof-of-concept code for a zero-day, dubbed "not-a-mused", that can turn Meta's Muse AI assistant into…A short excerpt from our source record; open the original for the full article.
AI-assisted analysis · . Based on linked headlines and available excerpts. Methodology · Report an error.