PUB-8B3BB7237BMeta Patches Zero-Day Vulnerability in Muse macOS AI Agent App
Security researcher Patrick Wardle discovered a zero-day vulnerability in Meta's Muse macOS application that allowed local code to hijack the AI agent's undocumented settings, redirect transcription endpoints, access user accounts, write malicious files, and take photos without alerting the user. Meta subsequently released a hotfix to patch the local privilege escalation vulnerability.
What happened
Security researcher Patrick Wardle discovered a zero-day vulnerability in Meta's Muse macOS application that allowed local code to hijack the AI agent's undocumented settings, redirect transcription endpoints, access user accounts, write malicious files, and take photos without alerting the user. Meta subsequently released a hotfix to patch the local privilege escalation vulnerability.
The vulnerability allowed significant unauthorized control over the AI agent and local device actions, but required existing local access on the victim's device and was quickly patched via a hotfix.
Evidence excerpts
- A zero-day vulnerability was discovered in Meta's Muse macOS application by security researcher Patrick Wardle.
- The vulnerability allowed local attackers to redirect transcription processing and leverage Muse's agent privileges to write files and take pictures without alerting users.
- Meta issued a hotfix to patch the local privilege escalation vulnerability.
Severity dimensions
Source citations
- Meta patches Muse exploit that let attackers control the AI agentThe Verge Artificial Intelligence · 2026-09-22