New: AI Beacon now tracks 7 AI platforms including Google AI Overviews in real time. See what's new →Add SEORCE as a preferred source on Google →
•by SEORCE Editorial, Search and marketing desk

Meta Muse AI security flaw let local apps steal account token

Wired disclosed the zero-day on September 23, 2026, and Meta issued a hotfix more than 12 hours later.

Add as a preferred source on Google

TL;DR

  • Wired reported on September 23, 2026 that a Muse zero-day let local processes capture a user's Muse account token.
  • Meta says Muse uses a dedicated cloud VM today, while Muse Confidential VM is planned for later in 2026 with trusted testers now.
  • Amazon began blocking Muse before Wired's disclosure, saying the agent violated Amazon's Conditions of Use for third-party purchasing tools.
  • Search and commerce teams should audit Muse-connected accounts, macOS permissions, checkout failures, and whether agent traffic is allowed by their terms.
Laptop with a transcription app window, terminal prompt, and redirected server connection path

The Meta Muse AI security flaw disclosed by Wired on September 23, 2026, let local apps or terminal commands redirect transcription and capture the token controlling a user's Muse account before Meta issued a hotfix. Wired attributed the discovery to Patrick Wardle, a macOS security researcher and founder of the Objective-See Foundation. Wired also reported that Amazon began blocking Muse from its site roughly 12 hours before Wardle disclosed the zero-day.

Meta's own Muse announcement says the personal AI agent is rolling out in the United States on iOS, Android, and muse.ai, with AI glasses support coming soon. Meta AI Research said on September 8, 2026 that Muse had been used internally since early 2026, and that Meta opened a public Muse bug bounty that day with awards up to $300,000. Social Media Today reported on September 27, 2026 that Meta had started a public trust push around Muse because the agent asks users for access to sensitive accounts and data.

What the Meta Muse AI security flaw did

The flaw let local code change an undocumented Muse setting that controlled where transcription occurred, according to Wired. Muse normally sent transcription to a Meta-operated server, but Wardle found that any locally installed app or executed terminal command could redirect that endpoint to an attacker-controlled server. Wired reported that the redirected endpoint would receive the token that authenticates the user to the Muse account, which gave the attacker control of the agent.

The flaw mattered because Muse had permissions and account access that ordinary malware would otherwise need to steal one by one. If an attacker controlled the Muse account token, Wired reported, the attacker could use Muse's own privileges to write files, take pictures, or access connected services through the agent.

Wardle told Ars Technica, in reporting republished by Wired, "We can manipulate the agent and leverage its privileges to do whatever we want." He added, "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself." Wired said Meta issued a hotfix more than 12 hours after its post went live, but the evidence does not say whether the fix changed the wider local settings model or only closed the token and transcription endpoint path.

How Muse is supposed to work

Meta says Muse runs on Muse Secure VM, a dedicated cloud computer with its own browser that houses the agent and the user's data. Meta says the agent checks with users before sensitive actions such as sending an email or making a purchase, and shows a complete audit trail of what it has done and plans to do. The product pitch is that Muse can search the internet, fill out forms, handle customer service, make purchases, create documents, and connect with apps and services.

Wired's report focused on the macOS implementation, which it described as an app with no Windows version. Wired said the macOS app worked with WhatsApp, email, calendar, and social media accounts, and could request operating system permissions for files, microphone, camera, location, and calendars. That matters because Apple's macOS permission model normally limits what local apps and terminal commands can do without user consent.

Meta's safety model for Muse is split between present controls and a future architecture. Meta AI Research says today's Muse architecture restricts Meta personnel access through operational policies, but does not prevent Meta from accessing data when needed to support, secure, or operate the service.

Meta AI Research says Muse Confidential VM, planned for later in 2026 and already used by a small group of trusted testers, is intended to cryptographically and verifiably prevent Meta from accessing data in a user's VM. Meta also says Muse does not share a person's conversations or VM data with Meta's ad systems, and that users can opt out of interactions being used to train Meta's AI models. Those statements do not remove the local security issue Wired described, because Wardle's attack used the user's own agent privileges after capturing the account token.

Where the evidence conflicts

The sources describe different surfaces of the same product, and the evidence does not resolve every product boundary. Meta's announcement names iOS, Android, and muse.ai for the United States rollout, while Wired describes a macOS app and says there is no Windows version. The record supplied here does not say whether the macOS app was part of the same public rollout, a companion client, or a separately distributed build.

SourceWhat it supportsWhat remains unknown
Meta announcementMuse uses Muse Secure VM and is rolling out on iOS, Android, and muse.ai in the United States.The evidence gives no exact announcement date beyond September 2026.
Meta AI ResearchPublic bug bounty opened September 8, 2026, with awards up to $300,000.The evidence does not say whether Wardle's flaw came through that bounty.
WiredA zero-day affected the macOS app and Meta issued a hotfix after publication.The evidence does not specify the hotfix version or changed code path.
Amazon statement in WiredAmazon blocked Muse as an "unauthorized AI agent [that] violates Amazon's Conditions of Use."The evidence does not say whether Amazon will allow Muse later.

Practitioner signal is thinner. One r/antiai post on September 28, 2026 said a user had created several accounts to exhaust Muse's stated 100GB free tier and waste compute, but that is one forum report, not a measurement of abuse at scale. It does show that some users are already looking for ways to impose cost or noise on Muse, which matters for operators who expose public forms, support workflows, or purchase paths to agents.

What search teams should check

Teams using Muse should first update any Muse client, then audit connected accounts inside Muse and revoke access that the agent does not need. On macOS, review Privacy & Security permissions for camera, microphone, files, location, calendars, and automation permissions granted to Muse, because Wired's report turns those permissions into the main risk multiplier. In Muse itself, check the audit trail Meta says the product provides, and record whether model-training opt-out is enabled for accounts that handle customer, finance, health, or campaign data.

For search, commerce, and paid media teams, the practical issue is agent-mediated discovery and conversion. Meta says Muse can search the internet, recommend insurance plans, make purchases, and handle customer service, so the agent can sit between a searcher and a site. That creates an inference for SEO and analytics work: pages that agents read for answers, policies, product data, and checkout rules may affect whether an agent cites, recommends, or completes a task, even when a human never views the same sequence of pages.

Amazon's block gives site owners a concrete policy model to consider. If an agent makes purchases or submits forms, review your own terms for third-party automated agents, then check checkout analytics for failed transactions, unusual form completion paths, and any logged application identity tied to Muse or other agents. If your stack cannot distinguish agent actions from human sessions, that gap should be treated as an analytics and fraud review item rather than a reason to assume the traffic is harmless.

What happens next

The next dated milestone is Meta's planned Muse Confidential VM rollout later in 2026. That is the feature to watch because Meta AI Research says it is intended to cryptographically prevent Meta from accessing VM data, while today's architecture relies on operational policies for Meta personnel access. Teams should also watch whether Meta publishes a hotfix version for the Wired flaw, whether Amazon removes its block, and whether bug bounty disclosures show more prompt-injection or local-client paths before Muse reaches AI glasses support.

FAQ

Is Meta Muse safe to use after the hotfix?

Meta says it issued a hotfix, but the supplied evidence does not prove Muse is safe in every deployment. Wired reported a specific zero-day involving transcription endpoint control and account tokens. Users should update the client, remove unnecessary connected services, and review operating system permissions before giving Muse access to sensitive accounts.

What data can Meta Muse access?

Muse can access the accounts, apps, and data a user connects to it. Meta's announcement describes a dedicated Muse Secure VM, a browser, user data, audit trails, purchase approvals, and email approvals. Wired reported that the macOS app could work with WhatsApp, email, calendars, social media accounts, files, camera, microphone, location, and other protected resources when granted permission.

Did Amazon block Meta Muse?

Yes, Wired reported that Amazon began blocking Muse from its site before the zero-day disclosure. Amazon said Muse was an "unauthorized AI agent [that] violates Amazon's Conditions of Use." The evidence does not say whether Amazon's decision came from the security flaw, commercial policy, customer safety concerns, or a mix of those issues.

Does Muse data train Meta AI models?

Meta says users can opt out of Muse interactions being used to train Meta's AI models. Meta also says Muse conversations and VM data are not shared with Meta's ad systems. Those statements concern Meta's internal use of data, not the separate risk Wired described, where an attacker could capture a token through a local-client flaw.

What is Muse Confidential VM?

Muse Confidential VM is Meta's planned architecture for cryptographically limiting Meta's access to data in a user's Muse VM. Meta AI Research says it is planned for later in 2026 and already in use with a small group of trusted testers. Today's Muse architecture, by Meta's own description, still allows access when needed to support, secure, or operate the service.