Meta fixes zero-day flaw in Muse macOS app after researcher hijacks AI agent
Security researcher Patrick Wardle found an unpatched setting in Meta's Muse macOS app that let local attackers reroute the app's cloud-based dictation to their own server, effectively seizing control of the AI agent. Wardle demonstrated the flaw by using Muse's own privileges to snap photos and write files to disk, often without alerting the user. Meta issued a hotfix within hours of the report, though it maintains the exploit required existing local access and posed low real-world risk.
The flaw shows how AI agents with broad system privileges can become an attacker's easiest tool—no need to write custom malware when you can hijack the assistant already trusted with device access. It also undercuts Meta's marketing of Muse's privacy and security credentials, raising questions about how thoroughly AI-agent products are vetted before release.
- Muse's cloud-based transcription setting was undocumented and exploitable by local attackers.
- The exploit let an attacker weaponize the AI agent itself instead of writing separate malware.
- Meta patched the bug quickly but downplayed its severity as requiring prior local device access.
Source: theverge.com — Jess Weatherbed, 2026-09-22
Published there as: “Meta patches Muse exploit that let attackers control the AI agent”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.