Meta patches Muse zero-day that let attackers hijack the AI agent
Meta patched a Muse macOS zero-day found by Patrick Wardle: an undocumented setting let local code redirect transcription to attacker servers and hijack accounts.

Updated
Why it matters
- Meta patched a zero-day in its Muse macOS app that allowed attackers to take control of the AI agent and access Muse accounts.
- Security researcher Patrick Wardle found the flaw, which used an undocumented Muse setting to redirect transcription from Meta's servers to an attacker-controlled endpoint, Ars Technica reports.
- The exploit required local access to the device; cloud-based dictation and open access to undocumented settings enabled the vulnerability.
Meta has patched a zero-day vulnerability in its Muse macOS app that could have let an attacker take full control of the AI agent and access a victim's Muse account.
Security researcher Patrick Wardle found the bug and disclosed it publicly on X. The exploit exploited an undocumented setting inside Muse that allowed code already running on a user's device to redirect transcription processing away from Meta's servers to an attacker-controlled endpoint, according to Ars Technica's report on the flaw. By intercepting that channel, the attacker gained access to the Muse account.
The attack required local access to the user's device, which narrows the pool of potential victims. But the severity of what an attacker could do once inside made the bug worth fixing fast. Muse is not a passive utility; it is an AI agent with broad reach into a user's workflow, and a compromised Muse account means a compromised assistant.
The mechanics matter here, because they point to a design problem rather than a single line of sloppy code. According to Ars Technica, several of Muse's design decisions combined to create the vulnerability.
The first is that Muse performs dictation in the cloud rather than on the device. That means the audio a user speaks — potentially containing passwords, private conversations, or sensitive work information — travels across a network connection to be transcribed. On-device transcription would keep that data local. Instead, Muse sends it to Meta's servers by default, which creates a redirectable channel.
The second decision is that Muse allowed any app on the machine to control all of its undocumented settings. That is the hinge of the exploit. An undocumented setting is invisible to the user and, in most threat models, invisible to scrutiny. An app with the ability to silently flip those settings could point Muse's transcription traffic at an arbitrary endpoint without the user ever seeing a prompt, a warning, or a configuration change.
Wardle — a well-known macOS security researcher who has spent years documenting exactly this class of privilege and permission flaw in Apple-platform software — identified the redirection mechanism as the path to account compromise.
The stakes extend beyond a single app. Muse sits in the vanguard of a new generation of AI agents that run continuously, read what is on screen, transcribe what is said, and act on a user's behalf across services. Those capabilities require broad permissions. Ars Technica's coverage framed Muse as an "extraordinarily privileged" assistant, and the phrase is the heart of the story: an agent with sweeping access is only as trustworthy as the weakest setting that governs it.
The industry is shipping these agents faster than it is establishing security boundaries around them. Meta is not alone in facing this problem — every major AI vendor is bolting agentic features onto assistants and operating systems — but Muse's cloud-based dictation and mutable hidden settings illustrate how the architecture of an agent, not just its code, determines its attack surface. A setting that any local app can change, which redirects where a user's speech is processed, is a design that assumes the local environment is trusted. On a modern personal computer, it is not.
For enterprises considering deployment of AI agents on employee machines, the incident is a concrete case study. The exploit did not require exotic techniques. It required a local foothold — something malware, a malicious app, or a compromised dependency routinely achieves — plus a target that exposes powerful, undocumented controls to whatever code is running alongside it.
Meta's patch closes the immediate hole. The company has not, based on the available reporting, detailed whether it has rearchitected the settings model or simply blocked the specific redirection path. That distinction will determine whether Wardle's finding was a one-off bug or a symptom of a structure that could produce more of them.
Users of the Muse macOS app should update immediately. Beyond that, the episode is likely to sharpen scrutiny of how AI agents handle the two things attackers want most: credentials and the data flowing through the agent itself.
Original: x.com
More from Marcus Bennett
Show full bio
Senior reporter covering consumer brands and retail at AI In Context.
124 articles
Related articles
- Meta Rushed to Patch a Zero-Day Bug in Its Muse AI Agent
- Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover
- Zero-Day in Meta's Muse AI Assistant Undoes macOS Defenses
- Meta Gives Muse Email Addresses, Video Calls, and Computer Access
- Developers Say Meta's Muse Hands Over Its Entire Filesystem on Request