English

SecurityMetaMuse

Meta patches zero-day exploit in Muse macOS app that allowed agent control

Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow an attacker to take control of the AI agent.

The flaw, identified by security researcher Patrick Wardle, exploited an undocumented setting within Muse. This allowed local code to redirect transcription processing from Meta’s servers to an attacker's endpoint, potentially granting access to the user's Muse account. Wardle demonstrated that the exploit enabled taking pictures and writing malicious files to disk, often without alerting the user.

Several design decisions contributed to the vulnerability, including the decision to perform Muse dictation in the cloud rather than on-device, and allowing any application to control Muse's undocumented settings.

Meta's Superintelligence Labs, represented by David Singleton, stated on X that the vulnerability was a local privilege escalation attack rather than a remote exploit. Singleton asserted that the practical risk to users was low because malicious code would need to already be running on the user's machine under their account. Meta issued the hotfix shortly after reports of the vulnerability were published.

Sources

  1. Meta patches Muse exploit that let attackers control the AI agent (The Verge AI, 2026-09-22)