Meta Patches Zero-Day Vulnerability in Muse AI Desktop App
A security researcher discovered a critical flaw in Meta's Muse app that permitted unauthorized control over the AI agent. Meta has since deployed a fix to address the vulnerability.

Discovery of the Muse Exploit
Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent, as detailed by [The Verge](https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent). The security flaw was identified by [security researcher Patrick Wardle](https://x.com/patrickwardle/status/2102045926474785265), who found that an undocumented setting in the software allowed potential attackers to manipulate the agent’s functionality.
Technical Scope of the Vulnerability
According to reports by [Ars Technica](https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/), the exploit functioned by utilizing an undocumented Muse setting. This configuration enabled attackers who already had local code running on a machine to redirect transcription processing from Meta's secure servers to their own endpoints. This redirection effectively granted the attacker access to the user's Muse account.
The vulnerability was facilitated by design choices that prioritized cloud-based dictation over on-device processing. Furthermore, the application permitted other apps to control its undocumented settings. During his testing, Wardle demonstrated that he could use the AI agent to take photographs and write malicious files to the disk without alerting the user.
Meta’s Response and Security Assessment
Following the report, David Singleton of Meta Superintelligence Labs [said on X](https://x.com/dps/status/2102248329111634067?s=20) that while the company released a hotfix, the actual risk to users remained minimal. Singleton characterized the incident as a local privilege escalation attack rather than a remote exploit. Because the attack required malicious code to be already active on the user’s machine, Meta argued that the threshold for a successful breach was high.
Despite this, Patrick Wardle remained critical of the development process. In his comments to researchers, he noted that security should be a foundational element of the architecture rather than an afterthought, stating, “At the very least, they should be thinking about security from the very start, and they are just not.”
Context and Broader Scrutiny
The security patch arrives at a sensitive time for Meta, which has faced mounting pressure since it first [announced the AI agent](https://www.theverge.com/ai-artificial-intelligence/991216/meta-bets-on-ai-agent-muse-to-catch-up-in-ai-race). The product launch has been marked by mixed reactions regarding its privacy implications and operational transparency. Concerns regarding the technology have been noted previously in discussions about whether [Meta’s Muse is creepy, but maybe not for the reasons you think](https://www.theverge.com/ai-artificial-intelligence/997833/meta-muse-creepy).
Additionally, the AI tool has faced friction with major tech entities. Notably, [Amazon recently blocked Muse](https://www.theverge.com/tech/998078/amazon-blocks-meta-muse-ai-agent-shopping) from its e-commerce platform, alleging that Meta did not seek proper authorization. Despite these challenges, the platform’s adoption rate has been rapid, with early download figures that have [reportedly outpaced ChatGPT’s](https://tech.yahoo.com/ai/meta-ai/articles/meta-muse-outpacing-chatgpt-early-191921038.html) debut, contributing to recent upward momentum in Meta’s stock value.
Sources
- The VergeMeta patches Muse exploit that let attackers control the AI agent