Skip to content
Tech News
← Back to articles

Meta fixes zero-day flaw in Muse macOS app after researcher hijacks AI agent

read original more articles
GoKawiil Brief

Security researcher Patrick Wardle found an unpatched setting in Meta's Muse macOS app that let local attackers reroute the app's cloud-based dictation to their own server, effectively seizing control of the AI agent. Wardle demonstrated the flaw by using Muse's own privileges to snap photos and write files to disk, often without alerting the user. Meta issued a hotfix within hours of the report, though it maintains the exploit required existing local access and posed low real-world risk.

Why It Matters

The flaw shows how AI agents with broad system privileges can become an attacker's easiest tool—no need to write custom malware when you can hijack the assistant already trusted with device access. It also undercuts Meta's marketing of Muse's privacy and security credentials, raising questions about how thoroughly AI-agent products are vetted before release.

Key Takeaways

Source: theverge.com — Jess Weatherbed, 2026-09-22

Published there as: “Meta patches Muse exploit that let attackers control the AI agent”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.