Meta patches zero-day in Muse that let attackers hijack the AI agent

Security researcher Patrick Wardle found a vulnerability in Meta's Muse app for macOS that gave anyone with local machine access control over the AI agent. The bug hinged on an undocumented setting that redirected transcription processing from Meta's servers to an attacker-controlled endpoint — handing over the user's account in the process. According to Ars Technica, two design choices made it possible: transcription runs in the cloud, not on-device, and any application can manipulate all of Muse's undocumented settings.
Wardle built proof-of-concept exploits that snapped photos and wrote malicious files to disk through Muse, mostly without alerting the user. "We can manipulate the agent and abuse its permissions to do whatever we want," Wardle said. "Instead of writing a comprehensive Mac info-stealer, you can just leverage the AI assistant itself. At minimum, they should have thought about security from the start, and they simply don't."
The flaw undercuts the privacy and security emphasis Meta highlighted when it unveiled the agent earlier this month. The company pushed an emergency fix within hours of the report going public and maintains the practical risk is low. David Singleton, from Meta's superintelligence labs, posted on X that this is a local privilege escalation, not a remote exploit — malicious code must already be running on the machine under the user's account. "That said, we've shipped a hotfix to the app to address the issue," he added.
The incident arrives as Meta's AI agent faces heightened scrutiny while the company races to close the gap with rivals. Amazon recently blocked Muse from its commerce platform, saying Meta never secured authorization. The launch still looks strong by the numbers: in its first 12 days, mobile downloads reportedly topped ChatGPT's U.S. and Canada debut, and Meta shares jumped 11% on Monday.