/Submit incident
Documented

Meta's Muse AI Assistant Vulnerability Enables Mac Hijacking

September 20, 2026
oecd:2026-09-20-bda1View source ↗

What happened

Meta's Muse AI assistant for macOS contains a zero-day vulnerability that allows attackers to hijack user accounts and gain full control over Macs. The flaw, discovered by security researcher Patrick Wardle, stems from Muse's privileged permissions and design, leading to unauthorized access and potential harm. Amazon has blocked Muse from its platform.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

OECD AI Incidents Monitor
Primary source
Meta's Muse AI Assistant Vulnerability Enables Mac Hijacking
2026-09-20