Meta rushes out Muse zero-day fix as agent privileges become the attack surface
Local code could hijack Muse's own privileges; the hotfix is out, and agent security design is the thing to watch.
Original event 2026-09-22
Meta has issued a hotfix for its Muse macOS app, closing a zero-day that let an attacker take control of the AI agent.
The flaw was found by security researcher Patrick Wardle: an undocumented Muse setting allowed code already running on the machine to redirect cloud transcription processing to an attacker-controlled endpoint, giving access to the Muse account. Wardle's proof-of-concept could take pictures and write malicious files through Muse, often without alerting the user.
The root cause is design: dictation runs in the cloud rather than on-device, and any app could change all of Muse's undocumented settings. Wardle said attackers need not write a full Mac malware stealer when they can simply leverage the assistant's own privileges.
Meta's David Singleton called it a local privilege escalation, not a remote exploit, and said practical risk was quite low — but the hotfix shipped within hours of the Ars Technica report.