Meta patches Muse exploit that let attackers control the AI agent

Meta has released a security update for its Muse macOS application after a researcher identified a zero-day vulnerability that allowed attackers to…

By Vane September 22, 2026 1 min read
Meta patches Muse exploit that let attackers control the AI agent

Meta has released a security update for its Muse macOS application after a researcher identified a zero-day vulnerability that allowed attackers to hijack the AI agent. Security expert Patrick Wardle discovered the flaw while testing the software and found it exploited an undocumented setting to redirect transcription data from Meta’s servers to a malicious endpoint. This technical misconfiguration granted the attacker full control over the user’s Muse account without requiring additional credentials or remote access to the machine.

The incident highlights specific architectural choices within the app that created this exposure. By processing dictation in the cloud rather than locally, the system relied on trust between the application and external servers that could be bypassed. Furthermore, the ability for any installed application to modify internal settings without restriction provided the necessary pathway for the exploit. This situation underscores the risks associated with granting broad permissions to third-party software when handling sensitive voice data.

  • The exploit required physical or local access to the user’s computer.
  • Redirected transcription traffic to an attacker-controlled server.
  • Granted the attacker complete control of the Muse account.
Scroll to Top