Un-Mused: How a Single Debug Setting Bypassed macOS Security in Meta’s AI Client
Meta's Muse agent had a debug setting that let any app hijack it. The fix is in — but the trust damage raises questions about how AI assistants handle permissions.

Why it matters
A zero-day in Meta's desktop AI agent exposed a fundamental security boundary flaw: unprivileged software could escalate to control a privileged assistant. This is a concrete example of agent-specific attack surface that practitioners deploying agents need to understand and vendors need to harden.
The key facts
7 to knowSecurity researcher: Patrick Wardle
Affected product: Meta's Muse desktop client for macOS
Vulnerability type: Zero-day, unpatched at disclosure, later hotfixed
Attack vector: Debug setting enabled privilege escalation
Impact: Input confidentiality compromised, account security at risk
Platform: macOS
Severity: Allows unprivileged software to manipulate assistant permissions
Go to the source
InfoQ AI/MLinfoq.com
Publisher excerpt: Security researcher Patrick Wardle revealed an unpatched zero-day vulnerability in Meta's Muse desktop client for macOS. This flaw lets unprivileged software manipulate the assistant's extensive permissions, compromising input confidentiality and account security. Despite a hotfix from Meta, the…