The Verge
Meta patches Muse exploit that let attackers control the AI agent
Tuesday, September 22, 2026
Meta released a patch for its Muse macOS app after security researcher Patrick Wardle identified a zero-day vulnerability that could allow attackers to take control of the AI agent. The vulnerability used an undocumented Muse setting that enabled attackers with local code execution to redirect transcription processing away from Meta's servers. Wardle disclosed the flaw through responsible disclosure practices. Meta did not disclose the number of users affected or whether the vulnerability was exploited before the patch was released.
Original reporting: https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent
