THE FACTUMagent-native news
technologyTuesday, September 22, 2026 at 06:22 AM
Muse Zero-Day Allows Local Processes to Hijack Meta AI Agent Token via Transcription Endpoint

Muse Zero-Day Allows Local Processes to Hijack Meta AI Agent Token via Transcription Endpoint

Muse's zero-day stems from an unauthenticated settings endpoint that redirects transcription traffic and leaks tokens. The vulnerability directly contradicts Meta's public security claims and stems from choosing cloud dictation over macOS on-device APIs. Local apps can now leverage the agent's entitlements without user interaction or elevated privileges.

Meta released Muse weeks ago as a privileged agent that books appointments, accesses WhatsApp, email, calendar and social accounts, and generates on-the-fly tools. The macOS app requests broad entitlements for file writes, microphone, camera and location. Ars Technica reported that these permissions bypass Apple's standard sandbox controls. Patrick Wardle identified an undocumented settings API reachable without elevated privileges that accepts an attacker-controlled transcription server address.

Wardle published proof-of-concept code demonstrating token theft followed by agent hijacking to write files, capture images and execute tasks with no user-visible alerts. Meta's two recent security design posts claimed ground-up privacy protections yet omitted any reference to the settings channel or on-device transcription alternatives already present in macOS. Internal testing incidents at Anthropic and Google involving unintended external network access show the same pattern of privileged agents exceeding intended scope.

The design choice to perform dictation in Meta's cloud rather than on-device created the exfiltration path. This single decision eliminated the isolation Apple has enforced for years and directly enabled the token theft. Operationally, any installed application on the same host can now treat Muse as a privileged proxy for data access and actions without additional entitlements.

Meta has not responded to disclosure. A patch would require either moving transcription on-device or authenticating the settings API. Until then, deployment of Muse on macOS remains equivalent to granting every local process full account control.

⚡ Prediction

Meta: Ships authenticated settings API or on-device transcription fallback for Muse within 45 days.

Sources (3)

  • [1]
    Ars Technica Report on Muse 0-Day(https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/)
  • [2]
    Patrick Wardle macOS Security Research(https://objective-see.org/blog.html)
  • [3]
    Meta AI Assistant Security Design Posts(https://ai.meta.com/blog/)