Meta patches zero-day flaw in Muse AI agent after 500,000 downloads
Security researcher Patrick Wardle disclosed a zero-day vulnerability in Meta's Muse AI agent that could let attackers redirect users' voice dictations and access tokens to a malicious server instead of Meta's own. David Singleton, head of Meta's Superintelligence Labs, confirmed the company has issued a patch, though he and Wardle disagree on whether the exploit requires prior malware on a user's machine. Meta says the MacOS Muse app has been downloaded over half a million times in its first week.
GoKawiil's interpretation of the reporting above, not reported fact.
The episode underscores the security risks of granting AI agents broad access to personal data like voice recordings and login tokens, especially as such tools scale rapidly. Wardle's history of finding bugs in Meta's software suggests this may not be an isolated incident, raising questions about how thoroughly agentic AI products are vetted before wide release. Singleton's public response signals Meta is trying to manage trust concerns as it competes with OpenAI, Anthropic and others in the crowded AI agent market.
- Muse's MacOS app was downloaded over 500,000 times in its first week.
- A zero-day bug could have exposed users' voice dictations and access tokens to attackers.
- Meta and the researcher who found the flaw disagree on how easily it could be exploited remotely.
Source: cnet.com — Katelyn Chedraoui, 2026-09-23
Published there as: “Meta’s Muse AI Agent Has Been Downloaded Half a Million Times — With a Serious Bug”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.