Muse agent zero-day is patched, but the design flaws remain
Meta rushed out a hotfix after a Muse zero-day let any local program seize account control; Amazon had already blocked the agent, and the underlying design choices stand.
Original event 2026-09-23
Meta's Muse assistant, launched only weeks ago, shipped with a zero-day: any local app or terminal command could rewrite the transcription server address and capture the account token, taking full control of the agent. Meta released a hotfix roughly 12 hours after disclosure.
The discoverer, macOS security expert Patrick Wardle, says attackers need not write full malware — the agent's own privileges suffice to write files or snap pictures with little or no indication. The root causes are design choices: cloud-based transcription, and any local process being able to control undocumented settings. The patch closes the hole; those decisions stand.
A separate fact: about 12 hours before disclosure, Amazon began blocking Muse from shopping on its site, calling it an unauthorized AI agent that violates its Conditions of Use, and asked Meta to remove Amazon from the experience. The exploit details are Wardle's own proof-of-concept, not independently reproduced; he plans to present them at a security conference in November.