Meta patches Muse exploit that let attackers control the AI agent
The Verge Jess Weatherbed ● Covered by 12 sources
Meta patched a zero-day in its Muse Mac app. A local attacker could steer transcription to their server and reach a Muse account.
Based on reporting by The Verge, Jess Weatherbed — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Meta has patched a zero-day vulnerability in Muse, its macOS app for the AI agent. The flaw could let an attacker take control of Muse, but only if they already had local access to the victim’s device.
Security researcher Patrick Wardle found the bug. It relied on an undocumented Muse setting that let local code redirect transcription processing away from Meta’s servers and to an attacker’s endpoint instead. That change could expose the Muse account tied to the session.
The setup was fragile in a couple of ways. Muse handles dictation in the cloud rather than on the device, and any app on the Mac could apparently manipulate Muse’s undocumented settings. Put those together and a hidden control surface becomes a problem fast.
This was a zero-day, so Meta was patching after the issue was already known. The bigger lesson is older than this one app: when a product keeps secret knobs around and lets other software poke them, security gets very expensive very quickly.
My take — AI-written commentary, not fact-checked reporting
This is the kind of bug that makes “AI agent” sound a lot less magical and a lot more like a very busy liability. Cloud dictation plus undocumented controls is exactly the sort of setup that invites trouble, then acts surprised when trouble shows up. Secret settings are not a security strategy; they’re a future headline.
Read more about this at: The Verge
Related stories
An AI model from Meta also hacked another company during testing
Simon Willison's Weblog · 1 month ago ·
11