{"slug": "meta-just-patched-a-major-zero-day-vulnerability-in-its-muse-ai-assistant", "title": "Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistant", "summary": "Meta issued a hotfix for a zero-day vulnerability in its Muse AI assistant for Mac, patching a flaw in the dictation feature that could let an attacker with existing code on a user's machine redirect dictated audio and an authentication token to a server they control. David Singleton of Meta Superintelligence Labs said the fix removed the internal setting that allowed the dictation server endpoint to be changed, calling it a local privilege escalation attack rather than a remote exploit; Mac security researcher Patrick Wardle, who disclosed the flaw Monday, said it could still be abused via a ClickFix-style attack. The patch follows Amazon's confirmation Monday that it asked Meta to stop letting Muse shop on Amazon.com on users' behalf, citing no advance notice, the agent's failure to identify itself, and concerns over credential and account data handling.", "body_md": "Meta’s do-it-all AI assistant Muse launched two weeks ago, and the company has already had to patch a pretty serious zero-day vulnerability in its app for Mac computers.\n\nDavid Singleton, who works at Meta Superintelligence Labs, said shortly after midnight Tuesday that the company had issued a “hotfix” for the vulnerability.\n\nMeta [launched Muse on Sept. 8](https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/) as a personal AI agent that can handle tasks like sending emails, booking travel, shopping, and tracking goals. To do all that, users give Muse access to a wide range of apps, accounts, and device features, making any vulnerability that could hijack the agent particularly concerning.\n\n“We strive to be extremely transparent about privacy and security in Muse as we know this is important to maintain your trust,” Singleton wrote in a [post](https://x.com/dps/status/2102248329111634067) on X explaining the issue.\n\nThe vulnerability involved Muse’s dictation feature, which sends audio to Meta’s servers for transcription rather than processing it locally on a user’s Mac.\n\nAccording to Singleton, the version of Muse that shipped included an internal setting that allowed developers to change the server endpoint used for the dictation feature, something he said was useful for debugging and development. The problem was that the setting lives on the app’s local preferences and could be changed by other programs running under the user’s account.\n\nThat meant an attacker who already had code running on the Mac could redirect Muse’s dictation traffic to a server they controlled. That server could then receive the user’s dictated audio along with an authentication token for their Muse account.\n\nFrom there, an attacker could effectively hijack Muse and take advantage of permissions the user had already given the assistant.\n\nThe vulnerability was discovered by Mac security researcher Patrick Wardle, who disclosed his findings Monday. [Wardle told Ars Technica](https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/) that he developed several proof-of-concept attacks that did things like “writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.”\n\nMeta pushed back somewhat on how much danger the vulnerability actually posed, pointing out that an attacker first needed to get malicious code running on the victim’s computer.\n\n“This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low. Nonetheless, we have issued a hotfix to the app to address the issue,” wrote Singleton.\n\nSingleton said Meta fixed the vulnerability by removing the setting that allowed the dictation endpoint to be changed.\n\nWardle, however, argues that requiring code to already be running on a Mac doesn’t necessarily make the flaw difficult to exploit. He said that it could be abused through a ClickFix-style attack where a victim is tricked into copying and running a malicious command on their computer.\n\nThis isn’t the only trouble Muse has run into since launch.\n\nAmazon [confirmed](https://gizmodo.com/amazon-brings-down-the-hammer-on-metas-muse-ai-agent-2000814878) to Gizmodo on Monday that it had asked Meta to stop allowing Muse to shop on Amazon.com on users’ behalf. Amazon said Meta did not notify the company in advance that Muse would be accessing its site and that the agent does not identify itself while shopping. The company also raised concerns about how Muse handles customer credentials and account data.\n\nMeta did not immediately respond to a request for comment.", "url": "https://wpnews.pro/news/meta-just-patched-a-major-zero-day-vulnerability-in-its-muse-ai-assistant", "canonical_source": "https://gizmodo.com/meta-just-patched-a-major-zero-day-vulnerability-in-its-muse-ai-assistant-2000815429", "published_at": "2026-09-22 15:40:57+00:00", "updated_at": "2026-09-22 15:53:19.872984+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-products", "ai-safety"], "entities": ["Meta", "Muse", "David Singleton", "Meta Superintelligence Labs", "Patrick Wardle", "Amazon", "Ars Technica", "Gizmodo"], "alternates": {"html": "https://wpnews.pro/news/meta-just-patched-a-major-zero-day-vulnerability-in-its-muse-ai-assistant", "markdown": "https://wpnews.pro/news/meta-just-patched-a-major-zero-day-vulnerability-in-its-muse-ai-assistant.md", "text": "https://wpnews.pro/news/meta-just-patched-a-major-zero-day-vulnerability-in-its-muse-ai-assistant.txt", "jsonld": "https://wpnews.pro/news/meta-just-patched-a-major-zero-day-vulnerability-in-its-muse-ai-assistant.jsonld"}}