
Meta patches Muse zero-day that let attackers hijack its AI agent
Meta shipped a hotfix for its Muse macOS app after researcher Patrick Wardle found a zero-day that let local code redirect dictation processing and seize control of the AI agent's account.
Meta has issued a hotfix for its Muse macOS app after security researcher Patrick Wardle discovered a zero-day vulnerability that could let an attacker take control of the AI agent. According to Ars Technica, the flaw relied on an undocumented Muse setting that allowed code already running on a machine to redirect transcription processing from Meta's servers to an endpoint chosen by the attacker, giving that attacker access to the victim's Muse account.
What the exploit could do
Several design decisions enabled the problem: Muse's dictation takes place in the cloud rather than on the device, and any application could change all of Muse's undocumented settings. Wardle built proof-of-concept attacks that used the agent to take pictures and write malicious files to disk, in many cases without alerting the user.
"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars Technica. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself." He added that Meta "should be thinking about security from the very start, and they are just not."
Meta: a local attack, with low practical risk
Meta patched the vulnerability within hours of the Ars Technica report and said real-world security concerns were minimal because the exploit required local access to the user's device. "This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user's machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low," David Singleton of Meta Superintelligence Labs wrote on X. "Nonetheless, we have issued a hotfix to the app to address the issue."
Timing and wider scrutiny
The fix lands while Muse is already drawing attention. Amazon recently blocked the agent from its e-commerce platform and says Meta never obtained permission for that access. The launch has nevertheless gone well for Meta: estimated downloads of the Muse mobile app in its first 12 days reportedly outpaced ChatGPT's own 12-day debut in the US and Canada, and Meta's stock climbed 11 percent on Monday.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.