{"id":257125,"date":"2026-09-22T15:15:02","date_gmt":"2026-09-22T12:15:02","guid":{"rendered":"https:\/\/digitrendz.blog\/z\/?p=257125"},"modified":"2026-09-22T15:15:02","modified_gmt":"2026-09-22T12:15:02","slug":"meta-fixes-muse-exploit-that-let-attackers-control-ai-agent","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/tech-news\/257125\/meta-fixes-muse-exploit-that-let-attackers-control-ai-agent\/","title":{"rendered":"Meta Fixes Muse Exploit That Let Attackers Control AI Agent"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Meta released a patch for its Muse macOS app after security researcher Patrick Wardle discovered a zero-day vulnerability.<br>&#8211; The flaw allowed attackers with local access to redirect transcription processing and take control of the AI agent&#8217;s privileges.<br>&#8211; Wardle demonstrated that the exploit could be used to manipulate the agent, take pictures, and write malicious files without user alerts.<br>&#8211; Meta responded by issuing a hotfix and downplaying the risk as a local privilege escalation rather than a remote exploit.<br>&#8211; Despite the security issue, Muse has seen high download rates surpassing ChatGPT&#8217;s debut, though Amazon recently blocked its e-commerce access.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">M<\/mark>eta has released an urgent update for its <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/muse\/\" class=\"acp-entity-link\" data-entity-id=\"113238\" data-entity-category=\"product\" title=\"Learn more about Muse\" target=\"_blank\" rel=\"noopener noreferrer\">Muse<\/a> <a href=\"https:\/\/digitrendz.blog\/z\/entity\/macos\/\" class=\"acp-entity-link\" data-entity-id=\"7265\" data-entity-category=\"Technology\" title=\"Learn more about macOS\" target=\"_blank\" rel=\"noopener noreferrer\">macOS<\/a> application<\/strong> to resolve a critical <strong><a href=\"https:\/\/digitrendz.blog\/z\/topic\/zero-day-vulnerability\/\" class=\"acp-topic-link\" data-topic-id=\"45133\" title=\"Explore: zero-day vulnerability\" target=\"_blank\" rel=\"noopener noreferrer\">zero-day vulnerability<\/a><\/strong> that allowed attackers to hijack the AI agent. The flaw, identified by security expert <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/patrick-wardle\/\" class=\"acp-entity-link\" data-entity-id=\"300517\" data-entity-category=\"Person\" title=\"Learn more about Patrick Wardle\" target=\"_blank\" rel=\"noopener noreferrer\">Patrick Wardle<\/a><\/strong>, exploited an undocumented configuration option within the app. This setting permitted malicious actors executing code locally to reroute transcription tasks from <a href=\"https:\/\/digitrendz.blog\/z\/entity\/meta\/\" class=\"acp-entity-link\" data-entity-id=\"252\" data-entity-category=\"Organization\" title=\"Learn more about Meta\" target=\"_blank\" rel=\"noopener noreferrer\">Meta<\/a>\u2019s secure servers to endpoints they controlled. By intercepting this data flow, an attacker could gain unauthorized access to the user\u2019s Muse account, effectively bypassing standard security protocols.<\/p>\n\n<p class=\"wp-block-paragraph\">The vulnerability stemmed from several architectural choices, most notably the decision to process dictation in the cloud rather than on the device itself. Additionally, the software allowed any installed application to modify all of Muse\u2019s hidden settings without restriction. Wardle demonstrated the severity of these design flaws through proof-of-concept attacks that enabled him to capture screenshots and write malicious files to the disk. In many instances, these actions occurred without alerting the user, highlighting significant gaps in transparency and control.<\/p>\n\n<p class=\"wp-block-paragraph\">Wardle emphasized the potential dangers of such privileges. \u201cWe can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself,\u201d he told <a href=\"https:\/\/digitrendz.blog\/z\/entity\/ars-technica\/\" class=\"acp-entity-link\" data-entity-id=\"223005\" data-entity-category=\"Organization\" title=\"Learn more about Ars Technica\" target=\"_blank\" rel=\"noopener noreferrer\">Ars Technica<\/a>. He further criticized the development approach, stating, \u201cAt the very least, they should be thinking about security from the very start, and they are just not.\u201d<\/p>\n\n<p class=\"wp-block-paragraph\">This revelation contrasts sharply with Meta\u2019s earlier marketing, which heavily promoted Muse\u2019s privacy and security features upon its launch. Meta moved quickly to patch the issue within hours of the report becoming public. Company officials argued that the immediate threat to users was limited because the exploit required prior local access to the victim\u2019s machine. <a href=\"https:\/\/digitrendz.blog\/z\/entity\/david-singleton\/\" class=\"acp-entity-link\" data-entity-id=\"204748\" data-entity-category=\"Person\" title=\"Learn more about David Singleton\" target=\"_blank\" rel=\"noopener noreferrer\">David Singleton<\/a> of <a href=\"https:\/\/digitrendz.blog\/z\/entity\/meta-superintelligence-labs\/\" class=\"acp-entity-link\" data-entity-id=\"44730\" data-entity-category=\"Organization\" title=\"Learn more about Meta Superintelligence Labs\" target=\"_blank\" rel=\"noopener noreferrer\">Meta Superintelligence Labs<\/a> clarified the nature of the risk on X: \u201cThis was a <a href=\"https:\/\/digitrendz.blog\/z\/topic\/local-privilege-escalation\/\" class=\"acp-topic-link\" data-topic-id=\"210047\" title=\"Explore: local privilege escalation\" target=\"_blank\" rel=\"noopener noreferrer\">local privilege escalation<\/a> attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user\u2019s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low,\u201d Singleton said. \u201cNonetheless, we have issued a hotfix to the app to address the issue.\u201d<\/p>\n\n<p class=\"wp-block-paragraph\">Despite the rapid resolution, the incident occurs during a period of intense scrutiny for Meta\u2019s AI initiatives. <a href=\"https:\/\/digitrendz.blog\/z\/entity\/amazon\/\" class=\"acp-entity-link\" data-entity-id=\"173\" data-entity-category=\"Organization\" title=\"Learn more about Amazon\" target=\"_blank\" rel=\"noopener noreferrer\">Amazon<\/a> recently blocked Muse from accessing its e-commerce platform, alleging that Meta failed to obtain necessary permissions. Nevertheless, the product\u2019s market reception remains strong. During its first twelve days, estimated downloads of the Muse mobile app reportedly surpassed those of <a href=\"https:\/\/digitrendz.blog\/z\/entity\/chatgpt\/\" class=\"acp-entity-link\" data-entity-id=\"389\" data-entity-category=\"Technology\" title=\"Learn more about ChatGPT\" target=\"_blank\" rel=\"noopener noreferrer\">ChatGPT<\/a>\u2019s debut in the US and Canada. Following the news of the fix and continued adoption, Meta\u2019s stock price rose by 11 percent on Monday, signaling investor confidence despite the technical setback.<\/p>\n\n<em>(Source: <a href='https:\/\/theverge.com\/tech\/998679\/meta-muse-patch-zero-day-exploit-ai-agent' target='_blank'>The Verge<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>Meta released an urgent hotfix for its Muse macOS app to patch a critical zero-day vulnerability that allowed attackers to hijack the AI agent via an undocumented configuration option. Security expert Patrick Wardle demonstrated how the flaw enabled unauthorized access to user accounts and system&#8230;<\/p>\n","protected":false},"author":1,"featured_media":257124,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,3247,6579,3297,3327],"tags":[133,157,218234,544,254908],"entities":[805,4416,986,161677,4652,749,31542,78310,257525],"class_list":["post-257125","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-artificial-intelligence","category-bigtech-companies","category-cybersecurity","category-newswire","tag-amazon","tag-chatgpt","tag-macos","tag-meta","tag-muse","entity-amazon","entity-ars-technica","entity-chatgpt","entity-david-singleton","entity-macos","entity-meta","entity-meta-superintelligence-labs","entity-muse","entity-patrick-wardle"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=257125"}],"version-history":[{"count":2,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257125\/revisions"}],"predecessor-version":[{"id":257143,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257125\/revisions\/257143"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/257124"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=257125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=257125"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=257125"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=257125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}