Meta patches Muse zero-day that let attackers hijack the AI agent
The Verge AI · rss · 2026-09-22
- Meta has patched a zero-day vulnerability in its macOS Muse app that could let attackers take control of the AI agent, discovered by researcher Patrick Wardle.
- The flaw abused an undocumented Muse setting: attackers running local code could redirect transcription processing from Meta's servers to their own endpoint, gaining access to the victim's Muse account.
- Design decisions enabling the bug included cloud-based dictation instead of on-device processing, and allowing any app to control all of Muse's undocumented settings. Local device access was required.
More from Safety
- OpenAI contractors fired for using AI to train the AI, 404 Media reports — 404 Media · 2026-09-22
- Anthropic's Real-World AI Intrusion Data on APT29 Deserves More Attention Than Doom Debates — jcran · 2026-09-22
- Would Frontier Researchers Accept an RSI Ban? Many Would Just Move Abroad — joshgans · 2026-09-22
- New Joshua Gans paper makes the economic case for AI provider cybersecurity liability — joshgans · 2026-09-22
- A curated reading list on AI biosecurity from RAND, CNAS and arXiv — davidmanheim · 2026-09-22
- Cerebras strategy chief: safety testing is becoming a growth driver for compute providers — RihardJarc · 2026-09-22