Meta Rushed to Patch a Zero-Day Bug in Its Muse AI Agent
Meta patched a zero-day flaw in its Muse AI agent that could leak audio dictations and access tokens, after 500,000 downloads in week one.

Updated
Why it matters
- Meta patched a zero-day bug in the Muse macOS app after researcher Patrick Wardle showed it could send dictations and access tokens to a malicious server.
- Muse was downloaded more than half a million times in its first week, per internal data seen by The Information.
- Meta's David Singleton confirmed the patch Tuesday; the disclosure came just before Wednesday's Meta Connect.
Meta patched a serious zero-day vulnerability in Muse, its new AI agent app for macOS, this week — after the app had already been downloaded more than half a million times in its first week, according to internal data seen by The Information.
Patrick Wardle, founder of the cybersecurity firm Objective-See, was the first to spot the bug. In posts on X, he demonstrated how an attacker could trick the AI agent into sending a person's Muse dictations — audio captures — and access tokens to a malicious server instead of Meta's. Wardle has a long history of finding flaws in Meta's software.
David Singleton, head of Meta's Superintelligence Labs, replied to Wardle's post on Tuesday and confirmed the company has patched the vulnerability. He argued that the bug required malware to already be present on a user's computer for the exploit to work. Wardle disagrees, saying a hacker could exploit the flaw remotely.
"We strive to be extremely transparent about privacy and security in Muse as we know this is important to maintain your trust," Singleton wrote.
If you run Muse on macOS, update the app now to get the security fix. No additional action is needed.
Why the stakes are unusually high
Muse appears as a cartoonish character at the top of Instagram feeds, and it wants to be your digital assistant. It entered an already crowded field of AI agents, including offerings from OpenAI, xAI and Anthropic. Its half-million first-week downloads make it one of the more popular choices in the category.
But popularity compounds risk. To get real value from an AI agent, users must grant it broad permissions. To make a dinner reservation, Muse needs control of the computer, web access, and potentially credit card information to hold the table. A bug that can reroute audio captures and access tokens is therefore not a minor flaw — it exposes exactly the credentials an agent holds by design.
A pattern, not a one-off?
Privacy and security remain two of the most serious unresolved problems in generative AI. No tech company has fully addressed the harms, whether cybersecurity attacks or the loss of control over personal information processed by these systems.
Meta carries more baggage than most AI startups. The 2016 Cambridge Analytica scandal revealed that millions of Facebook users' data had been used improperly. More recently, the company fought and settled a court battle over failing to protect children online. Transparency statements like Singleton's help, but much remains unknown about how agents like Muse actually handle the data they collect.
Timing: Meta Connect looms
The security reports landed just ahead of Wednesday's Meta Connect, where CEO Mark Zuckerberg is expected to detail the company's plans for AI and AI hardware. The event has traditionally centered on Meta's smart glasses, but public backlash — including the "pervert glasses" label earned through their recording capabilities — has cast doubt on the long-term viability of those devices.
The Muse incident lands in that same trust vacuum. Public faith in AI companies has dwindled recently, sharpened by AI researchers publicly warning that the technology could lead to human extinction.
If Meta intends to keep pushing into agentic AI, users will need evidence the company can build it responsibly — and a patched zero-day discovered by an outside researcher one week after launch is not the strongest opening argument.
Original: x.com
More from Elena Vasquez
Show full bio
Market editor covering media and advertising at AI In Context.
122 articles
Related articles
- Zero-Day in Meta's Muse AI Assistant Exposed User Accounts to Full Takeover
- Zero-Day in Meta's Muse AI Assistant Undoes macOS Defenses
- Developers Say Meta's Muse Hands Over Its Entire Filesystem on Request
- Meta Says Muse's Exposed Filesystem Is Intended Behavior
- Meta's Muse Hits 500,000 Users in Week One, Faces Copying Claims