Meta fixes Muse flaw allowing attackers to seize AI agent control

← Back to the feed

Meta fixes Muse flaw allowing attackers to seize AI agent control

The Verge · 24 minutes ago

Meta has patched a zero-day vulnerability discovered in its Muse macOS app that could allow attackers to take control of the AI agent. Security researcher Patrick Wardle found that the flaw exploited an undocumented Muse setting, enabling local attackers to redirect the app's transcription processing to their own servers and gain access to user accounts. The discovery is particularly significant because it contradicts Meta's stated emphasis on privacy and security when launching the agent earlier this month, and highlights potential design flaws in how the application handles sensitive operations.

The vulnerability worked because Muse performs dictation in the cloud rather than on-device and allows any application to control its undocumented settings. Wardle's proof-of-concept demonstrations showed the exploit could take pictures and write malicious files to the user's disk without triggering alerts. Meta patched the vulnerability within hours of the Ars Technica report being published, with company officials arguing the practical risk was low since the attack required malicious code already running locally on the user's machine. Despite the security lapse, Muse's commercial launch has been remarkably successful, with downloads in its first 12 days outpacing ChatGPT's own 12-day debut in the US and Canada, driving Meta's stock price up by 11 percent.

  • Meta patched Muse zero-day vulnerability allowing remote control of AI agent
  • Flaw exploited undocumented settings; required local access to device
  • Muse still performing commercially well despite security scrutiny

AI Research Science Software Technology

Read the full article at the source →

Originally published by The Verge as “Meta patches Muse exploit that let attackers control the AI agent”.