Inc. columnist Jason Aten says Meta's Muse agent synced his Mac texts up to row 187,462 while Full Disk Access showed as off. Meta says that cannot happen, so the dispute is over whether a settings screen shows users what an agent can actually read.
Perspective Coverage
5 publishers
- Builder
- Builder 34%
- Operator
- Operator 42%
- Investor
- Investor 24%
Reality
- Evidence40
- Adoption65
- Hype gap+30
- Incentives60
- Confidence55
Patrick Wardle found that any local process on a Mac can redirect Meta Muse's voice endpoint and capture its account token, with no macOS permission needed. Muse also zipped and exported the 6.8 GB root filesystem of its own sandbox on request.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
Dutch officials report root access and Monero miners on Macs with port 5900 open to the internet. Sonoma, Sequoia and Tahoe all need the update Apple shipped as an important security fix.
Perspective Coverage
5 publishers
- Builder
- Builder 22%
- Operator
- Operator 70%
- Investor
- Investor 8%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence68
The Dutch NCSC says CVE-2026-65400 was abused within two weeks of Apple's fix, with root access and Monero miners in every reported case. Patching closes the door; it does not evict anyone.
Perspective Coverage
6 publishers
- Builder
- Builder 22%
- Operator
- Operator 72%
- Investor
- Investor 6%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence62
A developer scanned their own MacBook from a second machine on the same network. The parts macOS ships were invisible; the exposure that stayed open was the dev servers they had left running, wider than they thought.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives65
- Confidence55
JFrog found that an unprivileged account on a Mac running Parallels Desktop 26.4.0 can reach the root dispatcher over a world-writable socket and run code as uid 0 through argument injection in the appliance installer.
Perspective Coverage
3 publishers
- Builder
- Builder 34%
- Operator
- Operator 48%
- Investor
- Investor 18%
Reality
- Evidence80
- Adoption42
- Hype gap+10
- Incentives55
- Confidence76
Patrick Wardle published working code that sends Muse's dictated audio to a server of the attacker's choosing. Because the assistant holds file, microphone, camera, calendar and paired-iPhone access, whoever redirects it inherits all of it.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 54%
- Investor
- Investor 13%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence65
Patrick Wardle showed that one undocumented key, endo_voyager_dictation_endpoint, let unprivileged local code reroute Muse's dictation audio and account token. Meta stripped the key from production builds and requested no CVE.
Reality
- Evidence58
- Adoption30
- Hype gap+20
- Incentives72
- Confidence55
Kaspersky says the macOS stealer it first tracked as Mac.c has swapped script droppers for FAT Mach-O binaries in a chain found in September 2026, and its loader now reads shell commands out of a public iCloud calendar file.
Reality
- Evidence68
- Adoption32
- Hype gap0
- Incentives58
- Confidence58
Patrick Wardle found that any locally installed app could repoint Muse's transcription endpoint and collect the token to an account already holding microphone, camera and disk permissions. Meta said it shipped a hotfix.
Reality
- Evidence66
- Adoption28
- Hype gap+55
- Incentives68
- Confidence62
JFrog says a non-admin account on a Mac can reach root through Parallels Desktop's dispatcher service by planting a double quote in a folder name. The change that stops it is in version 27, and that release needs Apple silicon.
Reality
- Evidence60
- Adoption25
- Hype gap+12
- Incentives65
- Confidence55
Huntress tracked nine months of malware campaigns run through shipped AI sharing features. Public Claude Artifacts, claude.ai/share links and indexable ChatGPT and Grok conversations all put the lure on a domain the victim already trusts.
Reality
- Evidence45
- Adoption38
- Hype gap+12
- Incentives85
- Confidence50
Microsoft says the campaign now delivers its payload through a command pasted into Terminal rather than a .dmg installer. The review step that mattered was tied to that older delivery method, and the attackers no longer need it.
Reality
- Evidence64
- Adoption52
- Hype gap+8
- Incentives68
- Confidence60
Huntress says a public proof of concept needs only an IP address to pull any file off unpatched Macs, driving a helper process that carries Full Disk Access.
Reality
- Evidence68
- Adoption42
- Hype gap+12
- Incentives62
- Confidence55
An authentication state flaw lets anyone who reaches TCP/5900 skip credentials entirely. Multiple cases reported to NCSC-NL ended in root and a Monero miner.
Reality
- Evidence34
- Adoption31
- Hype gap+18
- Incentives24
- Confidence41
Jamf Threat Labs describes a Rust stealer that copies Chromium profiles and drives them over Chrome DevTools Protocol. Password rotation does not revoke what it exports.
Reality
- Evidence64
- Adoption18
- Hype gap+14
- Incentives52
- Confidence58