A zero-day in Meta's Muse hands any local app the token to the whole account
Patrick Wardle found that any application or command on macOS can redirect where Muse sends speech for transcription. Pointing that address at an attacker's server delivers the token that authenticates the user to the account. Meta launched the agent on September 8, 2026 behind a security design it described at length, and it did not answer questions from Ars Technica. Amazon began refusing Muse on its own store on Sunday, September 20, 2026.
Source
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-dayArs Technica AI · Original published September 21, 2026
Muse is the agent Meta introduced on September 8, 2026 as a secure, private assistant that does the work instead of answering questions about it. Ars Technica reported on September 21, 2026 that the macOS version carries a zero-day with no fix behind it. Any locally installed application or executed command can change a list of undocumented settings, whatever permissions macOS granted it. One of those settings decides where speech goes for transcription.
How the token leaves
Transcription normally runs on a server Meta operates. Patrick Wardle, the macOS security researcher who found the flaw, showed that the address can be swapped for one the attacker controls. From that moment the attacker holds the token that authenticates the user to the Muse account, and with it the privileges of the agent itself.
Ars Technica describes one working form of the attack. The attacker's server sits between the user and Meta's endpoint as a proxy. A voice prompt passes through it, the server appends a malicious instruction, and the token travels to the same place. In the published example the instruction asks for an archive of the user's WhatsApp messages. Access becomes permanent rather than momentary.
Wardle said he built proof-of-concept attacks that write malicious files to disk and take photographs, in many cases with nothing shown to an attentive user.
Why the usual excuse does not hold here
Authors of software that can be abused once a machine is already compromised usually argue that everything is lost at that point anyway. Wardle's finding removes that argument. Ars reports that a simple variation of a ClickFix attack, where a person is talked into running something on their own machine, is enough to take over a Muse account.
What separates this from ordinary malware is the size of the prize. Running as Muse means inheriting everything the user connected to it: mail, calendar, WhatsApp and social accounts. On macOS the app's operating system permissions for disk, microphone, camera and location come along with them.
Two design decisions, named
Wardle names two choices. The first is that dictation happens in the cloud, where Meta can log it, although macOS has offered on-device transcription for years. The second is that any application can change all of those undocumented settings, which is reasonable for interface preferences and something else entirely for the address where speech is processed.
- Meta's launch post lists iOS, Android and the web for the United States rollout; Ars places the flaw in a macOS application.
- Meta says Muse has no visibility into passwords or payment methods, and that a separate Sentinel agent approves anything leaving the machine.
- Meta did not answer emailed questions from Ars Technica.
- Amazon told Ars that third-party applications buying on a customer's behalf should respect a service provider's decision about taking part, and that it asked Meta to remove Amazon from the experience.
Amazon closed its store first
Roughly 12 hours before the zero-day became public, Amazon started refusing Muse on its own site. Ars reports that people who tried were told Muse is an unauthorized AI agent that violates Amazon's Conditions of Use. The two events have no shared cause, and they hit the same product on the same day.
„We can manipulate the agent and leverage its privileges to do whatever we want.“
Sources
Related

Claude Code mods are not sandboxed, and version 2.1.289 fixes a deny rule they could override
Anthropic introduced mods for Claude Code on October 1, 2026. They are TypeScript functions, shipped inside plugins, that can rewrite prompts, change tool calls, and redraw parts of the interface. The documentation says mods are not sandboxed and run with your permissions, which covers your files, environment variables, and API keys. On Team and Enterprise plans a built-in mod named sec-default loads first and restricts the mods that users install. Versions 2.1.288 and 2.1.289 fix several cases where permission rules did not hold.
Anthropicverified
GitHub Copilot retires four models and makes Balanced its default code review effort
GitHub deprecated four models across all Copilot experiences on October 2, 2026: Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. On the same day it made Copilot code review available through the REST and GraphQL APIs. Balanced is now the default review effort level, a change that took effect on September 28, 2026. According to GitHub's documentation, a Balanced review consumes more AI credits than a Lite one.
GitHub Changelogverified

Apple will add controls to Full Disk Access on macOS, citing risks from AI agents
Apple said on October 2, 2026, that it will add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. The company says some developers use the permission in ways that expose files, mail, messages, and browsing history without users fully understanding it. Apple expects the risk to grow as AI agents become more capable and autonomous. The post gives no date, no macOS version, and no description of the new controls.
Appleverified

