Muse’s agent hijack: what privileged AI assistants actually put at risk
Muhammad Tayyab

Meta’s Muse Mac 0-day showed how a stolen agent token can reach email, WhatsApp, camera, and linked devices. A practical trust checklist for founders.
Meta’s Muse spent mid-September racing up the App Store charts as a personal AI agent that can email, shop, message, and act across your accounts. Within two weeks of launch, Amazon blocked it from shopping on Amazon.com — and macOS researcher Patrick Wardle showed that a local foothold on a Mac could steal the Muse authentication token and steer the assistant with every permission you had already granted.
This is not another abstract “AI safety” scare. It is a concrete reminder for founders and builders: once you hand a privileged assistant email, files, camera, or WhatsApp, its blast radius becomes the real product surface. Below is what happened, what was actually at risk, and a practical trust checklist before you connect the next agent to your life or your company stack.
What happened: Muse, a Mac foothold, and a stolen agent token
Meta introduced Muse on 8 September 2026 as a personal AI agent for the US on iOS, Android, and muse.ai, with WhatsApp as a chat surface. Unlike a chatbot that only answers, Muse is designed to do work: book appointments, fill forms, make purchases, open a browser, and connect to email, calendars, payments, and messaging. Meta marketed a Muse Secure VM, a separate Sentinel permission broker, and the familiar claim that the product was “built from the ground up for privacy and security.”
On 21 September 2026, Wardle (Objective-See Foundation) publicly disclosed a zero-day in the macOS Muse client. His proof of concept, not-a-mused, showed that any process already running as the logged-in user — no admin rights, no macOS permission prompt — could rewrite an undocumented preference: endo_voyager_dictation_endpoint.
That setting controls where Muse sends voice dictation for cloud transcription. Point it at an attacker-controlled server, wait for the user to tap the microphone and dictate, and the client ships raw audio plus the Muse account authentication token to the attacker. From there, an adversary can proxy traffic back to Meta so nothing looks broken, inject prompts the agent trusts, or reuse the token to control Muse silently.
Wardle’s demonstrations included writing malicious files, taking camera photos with little or no user-facing alert, and — via the hijacked agent — pulling location from a linked iPhone. As he told Ars Technica: instead of building a full Mac malware stealer, you can “just leverage the AI assistant itself.”
Important precision: this was not a remote Mac exploit by itself. It required local code execution first. Meta framed it that way after shipping a hotfix. The uncomfortable addendum — which Wardle and Ars both stressed — is that ClickFix-style social engineering (trick someone into pasting a Terminal command) is already one of the most effective ways to get that foothold on Macs. “Local only” on paper can still be remotely delivered in practice.
As of late September 2026 reporting, no public CVE had been assigned; Meta treated the issue as a configuration defect and removed the mutable debug-style preference from production builds.
Same week: Amazon blocks Muse shopping
Roughly a day before Wardle’s disclosure, Amazon began blocking Muse from shopping on its site. Users saw warnings that an unauthorized AI agent violated Amazon’s Conditions of Use. Amazon said it had not authorized Muse, that the agent did not identify itself, and that third-party agents should respect whether a service wants to participate.
That dispute is about agentic commerce and platform consent, not the Mac token bug. Together, though, they answer the same founder question: who trusts your agent, and what happens when that trust is misplaced?
Blast radius: what a privileged agent can actually reach
Personal agents only work if you grant them reach. Muse’s pitch — and the pitch of every serious competitor — depends on connectors and OS permissions:
- Email — read inboxes; often send on your behalf
- Messaging — WhatsApp and similar surfaces Meta already bridges
- Files and documents — create, move, and archive work product
- Camera and microphone — dictate, capture, verify
- Calendar, contacts, location — including cross-device linkage
- Payments and shopping — wallets, one-time cards, checkout flows
- Social and productivity apps — anything you authenticate into the agent
macOS spent years building Transparency, Consent, and Control (TCC) so random Terminal commands cannot casually touch those resources. A privileged assistant you intentionally authorize undoes that default. If an attacker owns the agent’s session token or can inject into its command path, they inherit the agent’s privileges — not the narrow permissions of their dropper.
That is the architectural shift. Infostealers used to chase browser cookies and keychains one by one. Privileged agents concentrate the same value behind one trusted process and one token.
Practical trust checklist (before you grant email, files, camera, WhatsApp)
Use this as a pre-flight for any personal or team agent — Muse, a coding agent with MCP tools, an inbox copilot, or an internal “do-everything” bot.
- Map the blast radius on paper. List every connector and OS permission the agent will hold. Ask: if this session is stolen tonight, what can an attacker read, send, spend, or capture without another prompt?
- Default to least privilege. Prefer read-only connectors. Require explicit re-approval for send, post, purchase, and file delete. If the product only offers “full access,” treat that as a product risk, not a convenience.
- Separate high-value identities. Do not connect your primary founder email, company admin WhatsApp, or production cloud consoles to a consumer agent on day one. Use a dedicated alias or sandbox account until the threat model is clear.
- Treat local agent clients as high-value endpoints. Desktop agents that store tokens or expose undocumented settings are as sensitive as password managers. Harden the Mac: auto-updates on, full-disk encryption, and no casual “paste this into Terminal” habits.
- Assume ClickFix is in scope. Never paste commands from fake CAPTCHAs, “download fix” pages, or spoofed Homebrew/Xcode installers. If your team installs tools via one-liners, pin known-good URLs and verify them out-of-band.
- Prefer OS-native sensitive pipelines when they exist. Wardle’s write-up highlighted cloud dictation as a design choice that made the Muse redirect possible; macOS already offers on-device dictation paths. When a vendor routes secrets or raw audio through mutable endpoints, ask why.
- Demand token hygiene in the architecture. Tokens that authenticate an agent with broad privileges should not be recoverable by arbitrary same-user processes. Ask vendors how session material is stored, rotated, and bound — and what a hotfix looks like when that assumption fails.
- Keep a kill switch ready. Know how to revoke connectors, sign out all sessions, rotate linked OAuth grants, and uninstall the desktop client in under five minutes. Practice it once.
- Watch the update channel. Agent clients move faster than enterprise patch cycles. Enable auto-update; after a public disclosure, verify the build number before you keep dictating into the mic.
- Respect third-party consent. If your agent shops, scrapes, or acts on external sites, assume those sites may block unidentified automation. Build for transparent agent identity and opt-in — Amazon’s Muse block is a preview of that norm.
When a hotfix isn’t enough
Meta’s macOS hotfix landed quickly — on the order of about twelve hours after Ars Technica’s report — and David Singleton of Meta Superintelligence Labs described the issue as a local privilege escalation with “quite low” practical risk because malware already had to be running under the user account.
Speed matters. So does framing.
A hotfix that removes one mutable preference closes that hole. It does not shrink the underlying privilege concentration. It does not erase ClickFix as an initial-access path. And it does not replace the need for users to:
- Update the client immediately after a disclosure
- Revoke and re-auth connectors if you suspect exposure
- Revisit which permissions still make sense after the incident narrative cools
Update hygiene for agent users: turn on automatic updates; subscribe to the vendor’s security notes (or reputable reporters); after any agent-hijack story, confirm you are on the patched build before granting new connectors; and treat “we shipped a hotfix” as the start of your review, not the end.
For builders shipping agents: strip debug endpoints from production, sandbox settings mutations, log permission-broker decisions outside the model, and assume researchers will treat your assistant as malware with a UI if you give it camera, files, and messaging in one package.
Soft close
Privileged assistants are useful. They are also a new class of high-value target. Muse’s launch week — chart momentum, an Amazon block, and a Wardle 0-day closed by hotfix — is a clean case study in why trust checklists beat marketing claims.
If you are evaluating agents for a product, a studio, or your own founder stack and want a second pair of eyes on architecture and blast radius, you can reach out via /#contact.
About the author
Muhammad Tayyab is a full stack and mobile engineer. He ships DripScore, an AI outfit-rating app on the App Store, under dawnapps.co.
- Site contact: iamtayyab.com/#contact
- Apps: dawnapps.co · DripScore on the App Store
- GitHub: github.com/meetayyab
- LinkedIn: linkedin.com/in/immtayyab
- X: x.com/iamtayyabx
Sources
- Introducing Muse (Meta Newsroom, 8 Sep 2026)
- Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day — Ars Technica (Dan Goodin, 21 Sep 2026)
- Meta patches Muse exploit that let attackers control the AI agent — The Verge (22 Sep 2026)
- Security Bite: The last 24 hours at Meta were “not-a-musing” — 9to5Mac (22 Sep 2026)
- Un-Mused: How a Single Debug Setting Bypassed macOS Security in Meta’s AI Client — InfoQ (24 Sep 2026)
- Amazon Blocks Meta’s Muse AI Agent From Shopping on Its Site — Business Insider (21 Sep 2026)
- Meta launches AI agent that can access other apps… — Reuters (8 Sep 2026)
- From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide — Microsoft Security Blog (5 Aug 2026)