Meta patches Muse exploit that let attackers control the AI agent
‘They should be thinking about security from the very start, and they are just not.’
‘They should be thinking about security from the very start, and they are just not.’
by
Jess Weatherbed
Sep 22, 2026, 11:53 AM UTC
Image: The Verge
Jess Weatherbed
is a news writer focused on creative industries, computing, and internet culture. Jess started her career at TechRadar, covering news and hardware reviews.
Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found bysecurity researcher Patrick Wardleutilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta’s servers to their own endpoint,Ars Technicareports, giving the attacker access to the Muse account.
Several design decisions reportedly enabled this flaw, including having Muse dictation occur in the cloud instead of on-device, and allowing any app to control all of Muse’s undocumented settings. Proof-of-concept attacks developed by Wardle to test the exploit enabled him to take pictures and write malicious files to disk via Muse, which did not alert the user in many cases.
“We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself,” Wardle toldArsTechnica.“At the very least, they should be thinking about security from the very start, and they are just not.”
Related
- Meta’s Muse is creepy, but maybe not for the reasons you think
- Inside the suddenly explosive world of AI safety
- A rogue AI led to a serious security incident at Meta
That stands in contrast with the emphasis that Meta placed on Muse’s privacy and security features when itannounced the AI agentearlier this month. Meta patched the vulnerability in the hours following theArsreport being published, and asserts that real-world security concerns were minimal because the exploit required local access to the user’s device.
“This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low,” David Singleton of Meta Superintelligence Labssaid on X. “Nonetheless, we have issued a hotfix to the app to address the issue.”
While quickly addressed, the Muse exploit comes at a time when Meta’s AI agent is already being scrutinized as the company tries to claw back ground from rival AI providers.Amazon recently blocked Musefrom accessing its e-commerce platform and claims Meta never obtained its permission to do so. Still, the launch has been successful for Meta — during its first 12 days, estimated downloads of the Muse mobile app havereportedly outpaced ChatGPT’sown 12-day debut in the US and Canada, with Meta stock climbing by 11 percent on Monday.
Follow topics and authorsfrom this story to see more like this in your personalized homepage feed and to receive email updates.
- Jess Weatherbed
Most Popular
Most Popular
- iPhone owners can now submit claims in Apple’s $250 million Siri AI settlement
- I got to see Google’s wild ideas about the future of laptops
- The M5 Ultra Mac Studio tears through our benchmark tests
- The long dream of the Googlebook
- Googlebooks feel like the first laptops built for Android owners
This is the title for the native ad