September 24, 20268 min read
Is Meta Muse Safe on Your Mac? What It Can Access, the Zero-Day, and How to Lock It Down
Meta's Muse agent can act across files, Messages, Mail and Calendar on a Mac. What it can reach, the dictation zero-day Meta says it fixed, and how to limit it.
The short answer
Meta Muse on Mac is only as safe as the access you give it. It can work with your files, Messages, Calendar, Notes and Mail (TechCrunch). On 21 September a researcher showed that a hidden setting let local malware redirect Muse's voice traffic (The Hacker News). Meta says it shipped a hotfix the next day (Gizmodo). Update it, connect only what you need, and don't use voice input until the fix is independently confirmed.
That is the practical answer. The rest of this article explains what Muse actually is, what it can reach on a Mac, what the zero-day was, and which settings matter.
What is Meta Muse?
Muse is Meta's personal AI agent. Meta launched it on 8 September 2026 on iOS, Android and the web, describing an assistant that sends emails, books travel and negotiates on your behalf, and learns your preferences over time (Meta Newsroom).
Meta says Muse is free for most of what people need, with subscription plans for heavier use (Meta Newsroom). It spread fast. Muse reached No. 1 on Apple's US App Store on 18 September, ten days after launch, with more than 730,000 US downloads in that period according to Sensor Tower data reported by Yahoo Tech. It was still the top free iPhone app on 22 September (Daring Fireball).
The Mac app arrived on 17 September. That is the version this article is about, because a desktop agent has a very different reach from a phone app (TechCrunch).
What can Muse access on your Mac?
On a Mac, Muse can work with Files, Messages, Calendar, Notes and Mail, according to TechCrunch's launch coverage. Meta has described Muse on Mac as able to operate apps on your desktop and keep working after you step away (TechCrunch).
Meta's position is that Mac access is opt-in and that the app "always asks before doing anything sensitive" (quoted by TechCrunch). Its launch post lists the safeguards it built in (Meta Newsroom):
| Meta's stated safeguard | What it means for you |
|---|---|
| Asks before sensitive actions, such as sending an email or making a purchase | You approve irreversible steps, if the agent classifies them correctly |
| A complete audit trail of what Muse did and plans to do | You can check its work after the fact |
| Disconnect services, or tell Muse to "forget" things | You can shrink its access and memory |
| Opt out of your interactions being used to train Meta's AI | Training use appears to be on unless you opt out |
| Conversations and VM data not shared with Meta's ad systems | Meta says Muse data stays out of ad targeting |
| Runs in a dedicated "Muse Secure VM" that houses the agent and your data | Your data sits in a separate environment; Meta says encryption via a "Confidential VM" comes later |
What no official source we could read lists is the exact set of macOS permissions Muse requests, such as Accessibility, Full Disk Access or Screen Recording. Check the prompts on your own Mac, and Meta's help page on how Muse works with files and apps, before granting them.
What was the Muse zero-day?
On 21 September 2026, Mac security researcher Patrick Wardle of Objective-See published a proof of concept against Muse for Mac (The Hacker News).
The problem was an undocumented setting that controls where Muse sends dictation. Any process running as the logged-in user could change it, with no extra macOS permission, and point Muse's voice traffic at a server the attacker controls (The Register). According to Malwarebytes, that exposed voice prompts and authentication tokens, which could lead to account takeover.
There is an important condition. The attack needs code already running on your Mac. Wardle and others argue that is realistic, because "ClickFix" scams routinely trick people into pasting commands into Terminal (Gizmodo). Wardle's own advice, as quoted by Malwarebytes, was blunt: don't install it.
Did Meta fix it?
Meta says yes. David Singleton of Meta Superintelligence Labs called it "a local privilege escalation attack, not a remote exploit," said the practical risk was "quite low," and said Meta had "issued a hotfix" early on 22 September (The Register; Gizmodo).
What's missing, as of 24 September: there is no public security advisory, no CVE and no fixed version number, and The Hacker News said it could not confirm what the change does. Wardle also disputes the "low risk" framing, citing how easily ClickFix-style scams get code onto Macs (Gizmodo). Treat the fix as claimed, not independently verified.
Why a desktop agent raises the stakes
A chatbot answers questions. A desktop agent reads your files and messages and acts in your apps, often while you're not watching. That makes it valuable, and it also means a single weakness exposes everything it can touch.
The Muse flaw is a clean example of the principle in our AI agent security guide: judge an agent by what it can do with your access before anyone notices. It is also why the most useful control is a human approval step before anything irreversible, which we cover in human-in-the-loop AI agents.
There is a second, quieter risk. Anything an agent reads, including a hostile email or web page, can try to steer it. Malwarebytes specifically warns about prompt injection in agents like Muse. If you have given Muse your Mail, our guide on giving an AI agent access to your email walks through that risk in detail.
How to lock down Muse on your Mac
If you use Muse, or are deciding whether to, these steps come from the researchers' advice and Meta's own controls:
- Update Muse now. Meta's hotfix only helps if you have it (9to5Mac).
- Connect the minimum. Don't give one agent your email, calendar and payments at once, and remove connections you don't use (Malwarebytes).
- Skip voice input for now. The zero-day targeted dictation traffic, and The Hacker News advises avoiding voice input.
- Review macOS permissions. In System Settings, under Privacy & Security, check what Muse has been granted and revoke anything it doesn't need (The Hacker News).
- Never paste Terminal commands from a web page or message. ClickFix scams use exactly this trick to get code onto a Mac (Gizmodo).
- Opt out of training if you prefer. Meta says you can opt out of your interactions being used to train its models (Meta Newsroom).
- Check the audit trail. Meta says Muse shows a complete record of what it has done and plans to do (Meta Newsroom). Review it, especially after Muse has processed email or web content.
- If you suspect compromise, treat Muse's connected accounts as exposed. Remove the app and reset those accounts' passwords and sessions (The Hacker News).
Why is Amazon blocking Muse?
Since 21 September, Amazon has blocked Muse from shopping on Amazon.com, showing a message that "unauthorized AI agent" access breaks its Conditions of Use (TechCrunch). According to GeekWire, Amazon says Muse didn't ask permission, doesn't identify itself as an agent, and captures and stores customer credentials. Meta responded that Muse "has no visibility into people's passwords or payment methods."
For users, the practical effect is that Muse can't complete Amazon purchases for now. The broader question, which sites will accept AI agents acting for customers, is one the whole industry is still settling. We covered the competing approaches in the personal AI agent race of 2026.
Common questions about Meta Muse safety
Is Meta Muse safe to install on a Mac?
It carries real risk because it can read and act across your files and apps. Meta says it hotfixed the 21 September dictation flaw, but there's no advisory or CVE yet. If you install it, update it, connect only what you need, avoid voice input for now and review its macOS permissions.
What can Meta Muse access on a Mac?
Muse for Mac can work with Files, Messages, Calendar, Notes and Mail, and Meta says it can operate apps on your desktop. Access is opt-in per app, and Meta says it asks before sensitive actions like sending email or buying something.
Does Meta use Muse data for ads or AI training?
Meta says Muse conversations and data in its secure VM are not shared with its ad systems. You can opt out of your interactions being used to train Meta's AI models, which suggests training use is on by default.
Is Meta Muse free?
Meta says Muse is free for most of what people need, with paid subscription plans for heavier use. Meta's launch post does not list prices.
Sources
- Introducing Muse, a personal AI agent, Meta Newsroom, 8 Sep 2026
- Meta's Muse hits Mac, letting the AI take actions on your computer, TechCrunch, 18 Sep 2026
- Everything new coming to Meta's AI agent Muse, TechCrunch, Sep 2026
- Meta's AI agent Muse hit No. 1 with fewer downloads, Yahoo Tech, 21 Sep 2026 (Sensor Tower data)
- One hidden Meta Muse setting could let attackers turn it into a backdoor, The Hacker News, 22 Sep 2026
- Meta Muse flaw lets local malware redirect dictation traffic, The Register, 21–22 Sep 2026
- Meta's Muse AI assistant has a zero-day, Malwarebytes, 22 Sep 2026
- Meta just patched a major zero-day in Muse, Gizmodo, 22 Sep 2026
- Security Bite: the last 24 hours at Meta, 9to5Mac, 22 Sep 2026
- Meta's AI agent has been blocked from Amazon.com, TechCrunch, 21 Sep 2026
- Amazon blocks Meta's Muse, GeekWire, 21 Sep 2026
Muse shows both sides of desktop agents: how useful they are, and how much a single flaw can expose. Vyra by Vyraagi is a desktop AI agent in closed alpha, designed to keep memory on your device and ask before any irreversible action. If that is the approach you want, join the waitlist.
Vyra is in closed alpha now, with a Founders Beta ahead of public launch.
Related reading
Is It Safe to Give an AI Agent Access to Your Email? What the Evidence Says
Email is the account AI agents get most often and the one that can reset all the others. The real risks, two documented attacks, and how to grant access safely.
AI Agents That Make Phone Calls for You: How Instinct and Meta Muse Calling Work, and Is It Legal?
Instinct and Meta Muse can now phone businesses for you, and Meta had humans make some calls. How AI calling works, the disclosure rules, and how to tell.
The Question to Ask Any AI Agent: What Can It Break Before Anyone Notices?
Agent safety is usually discussed as model alignment. The practical risk is simpler: what an agent can do with your credentials, unattended, before a human sees it.