Meta’s new AI assistant Muse has a reported zero-day vulnerability that could allow local attackers to take control of an entire Mac, macOS security researcher Patrick Wardle warned on X.
Wardle posted that, according to his analysis (and as first reported by other outlets), the flaw lets “local malware/attackers invisibly hijack” a user’s Mac via the Muse app. Meta currently does not offer a Windows version of Muse.
Muse vulnerability details
Wardle says the issue stems from the macOS permissions Muse requires. Those permissions allow an attacker to change the endpoint used for transcription (dictation). The server address normally points to a Meta-owned endpoint; by redirecting it to an attacker-controlled server, an attacker can obtain the token that controls the Muse account. From there, Wardle explained, an attacker does not need to install a specific trojan or run additional code to steal data — they can simply take control of Muse and use it to access information on the machine.
Muse operates as a personal AI agent that completes tasks and performs actions on a user’s computer, which requires broader system permissions than many third-party apps. Wardle also noted that other AI agents, such as OpenClaw, share similar security risks because of the permissions they request.
Meta response and Muse Secure VM
Meta anticipated potential security concerns tied to Muse’s extensive system permissions and addressed them at launch by designing Muse to run on “a dedicated secure computer with its own browser” called Muse Secure VM. Meta said, “Personal agents need a new kind of secure computer, so Meta built one for everyone,” and that “Muse Secure VM has first-of-its-kind privacy, safety, and security protections engineered into it that no other agent provides.”
Wardle further argued that specific design choices by Meta enabled the exploit. He pointed out that Apple keeps dictation processing local for its own apps and transcription features, while Meta elected to use the cloud for dictation — a choice Wardle said makes this type of exploit possible.

