Meta patches Muse exploit that let attackers control the AI agent
Summarized by AI from reporting by The Verge AI, published under our editorial policy.
Meta has patched a zero-day vulnerability in its Muse macOS app that could allow attackers to take control of the AI agent. The flaw was discovered by security researcher Patrick Wardle, who found an undocumented setting that enabled local code execution.

Key takeaways
- Meta has patched a zero-day vulnerability in its Muse macOS app that could allow attackers to take control of the AI agent.
- The flaw was discovered by security researcher Patrick Wardle, who found an undocumented setting that enabled local code execution.
- The patch is now available for all Muse users on macOS, and it is strongly recommended that users update their app as soon as possible.
Meta has released a patch for its Muse macOS app following the discovery of a critical zero-day vulnerability. The bug, found by security researcher Patrick Wardle, could allow attackers to take control of the AI agent. The flaw exploited an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta's servers.
What the vulnerability allowed
The zero-day vulnerability in Muse allowed attackers to execute local code, which could then redirect the AI agent's transcription processing. This meant that an attacker could potentially control what the AI agent did and how it processed information. The flaw was particularly concerning because it could be exploited without the user's knowledge, making it a significant security risk.
How Meta fixed the issue
Meta quickly responded to the discovery of the vulnerability by issuing a patch for the Muse app. The patch addresses the undocumented setting that was being exploited, effectively closing the door to potential attackers. The patch is now available for all Muse users on macOS, and it is strongly recommended that users update their app as soon as possible.
Why this matters to everyday users
This security flaw highlights the importance of keeping your software up to date, especially when it involves AI agents that handle sensitive information. For everyday users, this means that any app or service that uses AI to process data could be a potential target for attackers. By keeping your software updated, you can help protect yourself from similar vulnerabilities. It also serves as a reminder to be cautious about the permissions you grant to apps, especially those that handle sensitive data.
What you can do today
If you are a Muse user on macOS, the first step you should take is to update your app to the latest version. This will ensure that you have the patch that fixes the zero-day vulnerability. You can do this by opening the Muse app and checking for updates, or by downloading the latest version from the official Meta website. Additionally, always be cautious about the permissions you grant to apps and keep an eye out for any unusual activity that might indicate a security breach.
Frequently asked
- Is the Muse app safe to use now?
- Yes, the Muse app is safe to use now that the patch has been issued. However, it is important to update your app to the latest version to ensure that you have the necessary security fixes.
- What should I do if I suspect my Muse app has been compromised?
- If you suspect your Muse app has been compromised, you should immediately update the app to the latest version and review any permissions you have granted to the app. If you notice any unusual activity, you should also consider contacting Meta's support team for further assistance.