Meta patches Muse zero-day that let attackers hijack the AI agent
Meta released a hotfix for its Muse macOS app after a zero-day flaw allowed attackers to take control of the AI agent. Found by researcher Patrick Wardle, the bug used an undocumented setting to redirect transcription to an attacker's endpoint and required local access to the device.
- The flaw let attackers redirect Muse transcription to their own server
- Exploitation required malicious code already running on the user's machine
- Meta shipped a hotfix within hours of the report's publication
- Muse app downloads reportedly outpaced ChatGPT's first 12 days in the US
Read next
Security