AIToday
Large Language ModelsThe Verge AIPublished: Sep 22, 2026, 22:00 JST

Meta patches Muse exploit found by Patrick Wardle

Meta patches Muse exploit found by Patrick Wardle

3 Key Points

  1. What happened

    Meta patched a zero-day in its Muse macOS app after researcher Patrick Wardle found an undocumented setting let local code redirect transcription processing to an attacker's endpoint, Ars Technica reports.

  2. Why it matters

    Wardle's proof-of-concept took pictures and wrote malicious files via Muse, often without alerting the user, so an attacker could leverage the AI assistant itself instead of writing full Mac malware.

  3. What to watch

    Meta says real-world risk was low because the exploit required local device access, and it issued a hotfix; watch whether scrutiny grows as Amazon has blocked Muse from its e-commerce platform.

WHO IT HITSMac users running the Muse app and security teams evaluating AI desktop agents now have a concrete example of an agent's cloud processing and undocumented settings becoming an attack path, not just a convenience feature.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Context & Analysis

The flaw did not come from a single mistake but from several design decisions working together. Muse dictation ran in the cloud rather than on-device, and any app could control all of Muse's undocumented settings. Wardle's proof-of-concept showed that combination could let local code redirect transcription processing to an attacker's endpoint, and then use the agent's privileges to take pictures or write malicious files, often without alerting the user. That sits awkwardly beside the privacy and security emphasis Meta placed on Muse when it announced the agent earlier this month.

Meta moved quickly: it patched in the hours after Ars published its report, and David Singleton of Meta Superintelligence Labs argued the practical risk was low because the attack required local access under the user's own account. Still, the episode lands while Muse is already under scrutiny. Amazon recently blocked Muse from its e-commerce platform and says Meta never obtained permission, even as the launch drew strong early downloads and a stock climb.

The stakes come down to how much weight buyers put on that local-access caveat, and whether design choices like cloud dictation and broad app control over settings get revisited. Watch whether the hotfix closes the issue fully — or whether the scrutiny that already surrounds Muse continues to build.

FAQ
What did the Muse vulnerability let an attacker do?
It redirected transcription processing from Meta's servers to the attacker's endpoint, giving access to the Muse account, and Wardle's proof-of-concept could take pictures and write malicious files to disk.
Did the exploit require remote access?
No. Meta's David Singleton said it was a local privilege escalation attack requiring malicious code already running on the user's machine, so Meta called the practical risk low.
How quickly did Meta respond?
Meta patched the vulnerability in the hours following the Ars report being published, and Singleton said on X that a hotfix was issued.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Xiaomi open-sources MiMo-V2.6-Pro, tops open-weight AI indexSiliconANGLE AI · 2h ago
  • AI-exposed US jobs pay 46% more as entry roles vanishYahoo Finance AI · 2h ago
  • Epoch AI's JS Denain: no proof yet of imminent AI self-accelerationInterconnects (Nathan Lambert) · 2h ago

AI-summarized, only the topics you pick — one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleAmazon blocks Muse, but physical-world moat keeps deal alive