Meta launched Muse on September 8 with a bold promise. Its personal AI agent would send your emails and book your travel. It would also fill out forms and buy things for you, VentureBeat and Unite.AI report. To do that work, however, Meta Muse needs deep access to your digital life. Meta framed that access as safe by design. Within two weeks, two events tested that claim in public.
First, security researcher Patrick Wardle released a working exploit with a blunt warning: “Please don’t install. It’s trivial to turn Muse into the ultimate backdoor,” iTnews and Malwarebytes report. Second, Amazon blocked Muse from its store as an unauthorized AI agent. Neither story needs a CVE number to matter. Together, they point at the same weak spot. The access Meta sells as a feature is also the thing attackers want most.
What Meta Muse Can Reach
Muse is not a simple chatbot. According to VentureBeat, the Mac app arrived on September 17. With your permission, it can work inside your files, Mail, Messages, Calendar and Notes, MarkTechPost reports. It also keeps running in the background after you close the window. On top of that, users can connect work email and business tools by handing over API keys. Forkast and iTnews add that Muse also asks for camera and microphone access.
Demand has been huge. Muse passed 2.5 million downloads within 13 days, based on Sensor Tower data cited by VentureBeat and Forkast. In other words, millions of people have already handed this agent the keys to their machines.
To its credit, Meta built safety layers around all that reach. In its own security write-up, Meta says the agent runs inside an isolated runtime container. Meanwhile, a separate host program called Sentinel approves connector actions and controls network traffic. Meta also says the agent “never sees real tokens,” so a tricked agent cannot leak your passwords. The company even says it designed the system to “assume the agent may be under attack.” Unite.AI reported the same design details. On paper, that sounds careful. In practice, one hidden setting undid much of it.
How Wardle Hijacked Meta Muse
Wardle, founder of the nonprofit Objective-See, disclosed the flaw on September 21. He found an undocumented setting named endo_voyager_dictation_endpoint in Muse’s preferences, The Hacker News and TechRadar report. Any program running under your user account could change it. No special macOS permissions were needed. Once changed, the setting quietly sent Muse’s voice dictation to an attacker’s server instead of Meta’s.
That redirect opened the door wide. An attacker could read your spoken prompts and slip in new instructions for Muse to follow. Worse, the attacker could grab the token that signs you into Muse. With that token, someone could reach your account on every device where Muse runs, The Hacker News reports. In one demo, Wardle started on a Mac and then reached a linked iPhone. He pulled the phone’s location and quietly started a Bluetooth scan, VentureBeat and Runtime Wire report.
“We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.”
Patrick Wardle, security researcher
That line captures the real problem. Attackers no longer need to build complex spyware from scratch. Instead, they can borrow the powers you already gave your AI agent.
Meta’s Fix and the Fight Over Risk
Meta moved fast. Wardle confirmed a hot fix early on September 22, less than a day after his post, Unite.AI and VentureBeat report. According to VentureBeat, Meta simply removed the setting from production builds. That timing mattered, since Meta’s Connect conference opened on September 23, as Forkast notes.
Still, Meta pushed back on how serious the flaw was. David Singleton of Meta Superintelligence Labs called it “a local privilege escalation attack, not a remote exploit.” In his view, an attacker would already need malicious code running on your Mac. Wardle disagreed. He argued that a simple ClickFix attack, which tricks people into pasting a command, could deliver the hijack from afar, Forkast reports.
Both men make a fair point. However, malware landing on a Mac is not rare. When it does, Muse hands it a ready-made toolkit. Meta also has not published a formal security advisory, The Hacker News reports. According to InfoQ, the flaw has no official CVE number either.
Why Amazon Shut Meta Muse Out
Meanwhile, a second blow landed on the business side. On Sunday, September 20, Amazon began blocking Muse from its store. Shoppers saw a message warning that “continued access by an unauthorized AI agent violates Amazon’s Conditions of Use,” GeekWire and Mixed report. The block arrived just hours before Wardle went public on Monday.
Amazon gave several reasons. The company says Meta never told it Muse would shop there. It also says the agent hides the fact that it is an AI. An Amazon spokesperson added that shopping agents “should operate openly and respect service provider decisions about whether or not to participate.” Beyond that, Amazon flagged the risk of an agent that appears to store customer credentials.
Meta rejects that last charge. The company says Muse “has no visibility into people’s passwords or payment methods,” according to GeekWire and Mixed.
A Block With Mixed Motives
Amazon’s motives deserve a hard look, though. Tech Times points out that Amazon’s own Buy for Me agent shops other retailers’ sites without asking first. Instead, merchants must opt out by email. Money matters here too. Forbes and TechSpot note that Amazon earns about $68 billion a year from ads, and outside agents can skip right past sponsored listings. Amazon has also moved against shopping agents from OpenAI and Google.
So yes, the block serves Amazon’s bottom line. Even so, the security concern stands on its own. A major retailer looked at Muse and saw an unknown agent holding keys to customer accounts. Hours later, Wardle showed how a stranger could steal those keys.
What Meta Muse Users Should Do Now
The patch closes this hole, but the design question remains. VentureBeat found no enterprise view to match the audit trail Muse gives individual users. Meta’s documents describe no admin console for IT teams and no data loss prevention tools. Because Muse uses API keys instead of OAuth grants, security tools that watch only OAuth logins will miss it.
For now, treat Muse like any powerful app. Update it right away. Grant only the permissions a task truly needs, and turn off voice dictation if you do not use it. Be wary of any site that asks you to paste a command into Terminal, since that is how ClickFix attacks begin. At work, check with IT before you connect company email.
The Real Cost of Wide Access
Meta sold wide access as a feature it had made safe. Wardle’s hijack and Amazon’s block tell a different story. When one agent can see your files and speak for you online, that agent becomes the prize. Wardle plans to share more AI assistant flaws at Objective by the Sea in Hawaii this November, The Hacker News reports. Until the industry builds real controls around these agents, broad access is not security. Instead, it hands attackers a map of everything worth taking.

