# Researcher reports Meta Muse flaw that exposes Mac control token

_Published Tuesday, September 22, 2026 at 1:09 PM EDT · Security, AI · Latest · Tier 2 — Notable_

![Researcher reports Meta Muse flaw that exposes Mac control token — Primary](https://helios-i.mashable.com/imagery/articles/06QxOj6rCT5PAbx0OjYhO6V/hero-image.fill.size_1200x675.v1790091583.jpg)

Mac security researcher Patrick Wardle reported a zero-day vulnerability in Meta's Muse agent that could let malware already running locally redirect the app's cloud transcription endpoint and capture the token controlling a user's Muse account. An attacker could then use the agent's extensive permissions to access data or act on the Mac without deploying a separate data-stealing payload.

Wardle attributes the flaw to Muse's cloud-based dictation design. Meta had promoted a dedicated secure virtual machine for the agent but had not addressed the reported vulnerability when the article was published.

## Sources

- [Mashable](https://mashable.com/tech/meta-muse-ai-assistant-zero-day-vulnerability-mac)

---
Canonical: https://techandbusiness.org/newswire/Zc1b-CRAXCPLnAJqY99hUF
Published: 2026-09-22T17:09:09.927Z
Story chronology: 2026-09-22T15:55:24.000Z
Retrieved: 2026-09-22T18:38:31.693Z
Publisher: Tech & Business (techandbusiness.org)
