Signals
Is the Muse Mac Zero-Day Real? What Meta Patched, and Whether You Should Uninstall
By the Top5Apps editorial team · Published September 22, 2026 · Updated September 22, 2026 · 4 min read
Short answer: real, Mac-only, local, and patched. On September 21, security researcher Patrick Wardle published a proof of concept showing Muse for Mac exposed an undocumented setting that let code already running on your Mac turn the agent into, in his words, 'the ultimate backdoor.' Meta confirmed the bug and issued a hotfix in the early hours of September 22, calling it 'a local privilege escalation attack, not a remote exploit.' The iPhone, Android, and web versions were never affected. You don't need to uninstall — but you should make sure you're running the patched build, and Meta hasn't made that as easy as it should be.
What happened, in order
- Sept 17: Muse for Mac ships as a direct download from ai.meta.com — not through the App Store.
- Sept 21, 14:04 UTC: Wardle publishes the not-a-mused repository. Its README: 'Muse exposes an undocumented setting: endo_voyager_dictation_endpoint… This is a local attack.'
- Sept 21, 14:42 UTC: Wardle posts: 'Please don't install — it's trivial to turn Muse into the ultimate backdoor.'
- Sept 21, evening: Ars Technica covers it under the headline that Meta's 'extraordinarily privileged AI assistant has a serious 0-day.' Meta doesn't answer Ars' questions.
- Sept 22, 04:07 UTC: Meta's David Singleton confirms: 'We appreciate this report and have issued a hotfix to the Muse Mac app… Our hotfix removes the endpoint setting from production builds entirely, which closes this vulnerability.' He adds it 'does not involve Muse's servers or the Secure VM.'
- Sept 22, morning: The Verge reports Meta 'patched the vulnerability in the hours following the Ars report.'
Patrick Wardle@patrickwardle
Please don't install - it's trivial to turn Muse into the ultimate backdoor.
View original post ↗
What the bug actually was — and what 'local' means for you
Wardle's write-up describes an undocumented setting — the endo_voyager_dictation_endpoint string you've seen in searches — that code already on your Mac could abuse, and Meta's fix was to remove that setting from production builds entirely. 'Local' means the attacker already had to be running code on your Mac. Malware that was already there could use Muse to escalate what it's allowed to do. Nobody could reach your Mac through Muse from the internet, and Meta says the servers and the per-user Secure VM where your connected data lives were untouched.
So why did it get the 'ultimate backdoor' label? *Because of what Muse is.* An agent app holds OAuth tokens for your email and calendar, a credentials store for your other logins, and standing permissions to act as you. On a normal app, local privilege escalation is a bad bug. On an agent, it's a bug that hands malware your entire delegated life. That's Ars' point about 'extraordinarily privileged,' and it's the honest cost of installing any of these — Muse, Instinct, Grok Bot, or Claude.
The disclosure fight
Wardle published the proof of concept without reporting it to Meta first, as The Hacker News noted — a choice that split the security community along its usual seam. The case for: Muse had been #1 on the App Store for days and was being installed by exactly the people least able to evaluate it; a public warning got Meta moving in under fourteen hours. The case against: for those fourteen hours, a working exploit for a hidden setting sat on GitHub while the fix didn't exist, and Meta's own response makes clear a private report would have produced the same patch. Meta, for its part, thanked him publicly rather than fighting — the right call.
Should you uninstall Muse on Mac?
No — but verify you're patched, because Meta hasn't published a version number or a security advisory. Singleton's post is the entire public record of the fix. The Mac app isn't distributed through the App Store, so there's no store update to wait for. The safe move is to quit Muse and reinstall the current build from ai.meta.com/muse/download, which gets you the production build with the setting removed. If you want belt and braces, disconnect Gmail in Settings → Connectors and also revoke Muse at myaccount.google.com/connections, then reconnect after reinstalling.
Two clarifications for anyone searching the terms flying around this week. 'Sentinel' isn't a vulnerability — it's the name of Meta's permission component, 'the sole permission authority for connector actions and network egress,' from the Sept 8 architecture post. And the iOS app's version 8.0, released September 20, isn't 'the hotfix' — iOS didn't have the bug.
Our read
This went about as well as a zero-day can go: a local-only bug, a fix in hours, a public thank-you instead of a lawyer's letter. What it changes is the mental model. The pitch for personal agents is 'give it your logins and let it rip'; the lesson of September 21 is that the app holding those logins is now the highest-value target on your machine, and it has to be built and patched like one. Meta's ledger this week: a serious bug, a fast fix, and still no advisory, version number, or in-app notice — the last of which a company asking for your Gmail owes you. We've added the incident to our Muse review and the safety guide; the ranking doesn't change.
