Meta patches Muse exploit that let attackers control the AI agent
Zero-day in Meta's Muse agent: local code execution + undocumented settings = full account takeover. Patch now live.

Why it matters
Agent security vulnerability in production deployment. This is the kind of exploit that defines agent reliability in the wild — local access escalating to account compromise through design flaws (cloud dictation, loose permission model). Practitioners running agents need to audit similar architectural patterns.
The key facts
12 to knowZero-day vulnerability in Meta Muse macOS app discovered by security researcher Patrick Wardle
Exploit required local code execution; gave attackers full Muse account access
Attack vector: undocumented Muse settings allowed redirection of transcription processing from Meta servers to attacker-controlled endpoint
Root cause: cloud-based dictation + overpermissive app control of agent settings
Meta has issued patch
Published September 22, 2026
Meta Muse macOS agent vulnerable to zero-day exploit
Vulnerability discovered by security researcher Patrick Wardle
Attack required local device access; gave attackers account control
Flaw: undocumented Muse settings allowed redirecting transcription processing from Meta servers to attacker-controlled endpoint
Design issues: cloud-based dictation + any app able to control undocumented settings
Patch issued and deployed
Go to the source
The Verge AItheverge.com
Publisher excerpt: The zero-day exploit required local access to the user’s device, but gave potential attackers access to Muse accounts. | Image: The Verge Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The…